First published: Tue Mar 02 2010(Updated: )
Quoting httpd 2.2 security page: <a href="http://httpd.apache.org/security/vulnerabilities_22.html#2.2.15">http://httpd.apache.org/security/vulnerabilities_22.html#2.2.15</a> moderate: mod_proxy_ajp DoS <a href="https://access.redhat.com/security/cve/CVE-2010-0408">CVE-2010-0408</a> mod_proxy_ajp would return the wrong status code if it encountered an error causing a backend server to be put into an error state until the retry timeout expired. A remote attacker could send malicious requests to trigger this issue, resulting in a denial of service. Affects: 2.2.0 - 2.2.14 Upstream commit: <a href="http://svn.apache.org/viewvc?view=revision&revision=917876">http://svn.apache.org/viewvc?view=revision&revision=917876</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/httpd22 | <0:2.2.14-11.jdk6.ep5.el4 | 0:2.2.14-11.jdk6.ep5.el4 |
redhat/httpd | <0:2.2.3-31.el5_4.4 | 0:2.2.3-31.el5_4.4 |
redhat/httpd | <0:2.2.14-1.2.6.jdk6.ep5.el5 | 0:2.2.14-1.2.6.jdk6.ep5.el5 |
Apache Http Server | =2.2 | |
Apache Http Server | =2.2.0 | |
Apache Http Server | =2.2.2 | |
Apache Http Server | =2.2.3 | |
Apache Http Server | =2.2.4 | |
Apache Http Server | =2.2.6 | |
Apache Http Server | =2.2.8 | |
Apache Http Server | =2.2.9 | |
Apache Http Server | =2.2.11 | |
Apache Http Server | =2.2.12 | |
Apache Http Server | =2.2.13 | |
Apache Http Server | =2.2.14 | |
Apache Http Server |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2010-0408 is classified as moderate.
To fix CVE-2010-0408, upgrade to a patched version such as httpd 2.2.14 or later.
CVE-2010-0408 affects Apache HTTP Server versions up to 2.2.14.
Yes, CVE-2010-0408 can be exploited to cause a denial of service (DoS) condition.
Vulnerable packages to CVE-2010-0408 include httpd22 and httpd in versions earlier than 2.2.14.