REDHAT-BUG-509125: Low severity Apache mod_deflate vulnerability
François Guerraz reported in Debian BTS a possible DoS (CPU consumption) a DoS with moddeflate since it does not stop to compress large files even after the network connection has been closed. This allows to use large amounts of CPU if there is a largish file available that has moddeflate enabled.
Original report: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=534712
Post to the apache-httpd-dev mailing list: http://marc.info/?l=apache-httpd-dev&m=124621326524824&w=2
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-509125?
The severity of REDHAT-BUG-509125 is low.
How does REDHAT-BUG-509125 affect Apache mod_deflate?
REDHAT-BUG-509125 can lead to a denial of service by consuming excessive CPU resources when compressing large files even after the connection is closed.
What version of Apache is impacted by REDHAT-BUG-509125?
REDHAT-BUG-509125 impacts Apache mod_deflate.
Is there a workaround for REDHAT-BUG-509125?
Currently, there is no specified workaround for REDHAT-BUG-509125.
What should I do if my system is affected by REDHAT-BUG-509125?
If your system is affected by REDHAT-BUG-509125, monitor CPU usage and consider disabling mod_deflate until a fix is applied.