CVE-2009-1890

Impact:
Important
Public Date:
2009-07-02
CWE:
CWE-835
Bugzilla:
509375: CVE-2009-1890 httpd: mod_proxy reverse proxy DoS (infinite loop)

The MITRE CVE dictionary describes this issue as:

The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which allows remote attackers to cause a denial of service (CPU consumption) via crafted requests.

Find out more about CVE-2009-1890 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v2 metrics

Base Score 5
Base Metrics AV:N/AC:L/Au:N/C:N/I:N/A:P
Access Vector Network
Access Complexity Low
Authentication None
Confidentiality Impact None
Integrity Impact None
Availability Impact Partial

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 Server (httpd) RHSA-2009:1155 2009-07-14
Red Hat Application Stack v2 for Enterprise Linux (v.5) (httpd) RHSA-2009:1156 2009-07-14
Red Hat Enterprise Linux 5 (httpd) RHSA-2009:1148 2009-07-09
Red Hat JBoss Web Server 1.0 for RHEL 4 AS (httpd22) RHSA-2009:1160 2009-07-17

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.