CVE-2009-3094: Null Pointer Dereference
A NULL pointer dereference flaw was discovered in httpd's modproxyftp module. Malicious FTP server can use this flaw to crash httpd's child process via malformed reply to EPSV FTP command.
Problem was confirmed in both 2.0.x and 2.2.x httpd versions.
References: http://www.intevydis.com/blog/?p=59 http://secunia.com/advisories/36549/
Other sources
The approxyftphandler function in modules/proxy/proxyftp.c in the modproxyftp module in the Apache HTTP Server 2.0.63 and 2.2.13 allows remote FTP servers to cause a denial of service (NULL pointer dereference and child process crash) via a malformed reply to an EPSV command.
— Red Hat
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2009-3094?
CVE-2009-3094 is classified as a critical vulnerability due to its potential to crash the httpd child process.
How do I fix CVE-2009-3094?
To fix CVE-2009-3094, update the httpd package to version 2.2.10-25.1.ep5.el4 or a later version.
What software is affected by CVE-2009-3094?
CVE-2009-3094 affects the Apache HTTP Server versions 2.0.x and 2.2.x.
What is the exploit method for CVE-2009-3094?
CVE-2009-3094 can be exploited by a malicious FTP server sending a malformed reply to the EPSV FTP command.
Which systems are vulnerable to CVE-2009-3094?
Systems running vulnerable versions of the httpd package, particularly in Red Hat environments, are susceptible to CVE-2009-3094.