Description
The ap_proxy_ajp_request function in mod_proxy_ajp.c in mod_proxy_ajp in the Apache HTTP Server 2.2.x before 2.2.15 does not properly handle certain situations in which a client sends no request body, which allows remote attackers to cause a denial of service (backend server outage) via a crafted request, related to use of a 500 error code instead of the appropriate 400 error code.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2035-1 | New apache2 packages fix several issues |
Ubuntu USN |
USN-908-1 | Apache vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-07T00:45:12.250Z
Reserved: 2010-01-27T00:00:00.000Z
Link: CVE-2010-0408
No data.
Status : Modified
Published: 2010-03-05T16:30:00.660
Modified: 2026-04-29T01:13:23.040
Link: CVE-2010-0408
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
Ubuntu USN