VDB
CVE-2004-0492
CVE-2004-0492
PUBLISHED
CVSS 10 CRITICAL
Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes a large amount of data to be copied.
EPSS 33.64% · 98.2th percentile
Risk Scores
CVSS 2.0
10
EPSS Score
33.64%
98.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| hp | webproxy | 2.1, 2.0 |
| apache | http_server | 1.3.31, 1.3.29, 1.3.27 |
| ibm | http_server | 1.3.26.2, 1.3.26, 1.3.26.1 |
| sgi | propack | 2.4 |
| n/a | n/a | n/a |
| openbsd | openbsd | 3.4, 3.5 |
| hp | virtualvault | 11.0.4 |
| hp | vvos | 11.04 |
Timeline
- CVE Published
- Sep 23, 2010 PoC Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Oct 31, 2023 EPSS Score
References
- 20040611 [OpenPKG-SA-2004.029] OpenPKG Security Advisory (apache) mailing-list
- RHSA-2004:245 vendor-advisory
- http://www.guninski.com/modproxy1.html url
- oval:org.mitre.oval:def:4863 vdb
- 101841 vendor-advisory
- [httpd-cvs] 20210330 svn commit: r1073139 [1/13] - in /websites/staging/httpd/trunk/content: ./ security/json/ mailing-list
- [httpd-cvs] 20210330 svn commit: r1073139 [3/13] - in /websites/staging/httpd/trunk/content: ./ security/json/ mailing-list
- [httpd-cvs] 20210330 svn commit: r1073149 [4/13] - in /websites/staging/httpd/trunk/content: ./ security/ security/json/ mailing-list
- 57628 vendor-advisory
- oval:org.mitre.oval:def:100112 vdb
- MDKSA-2004:065 vendor-advisory
- DSA-525 vendor-advisory
- HPSBOV02683 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2004-0492 advisory
- https://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5@%3Ccvs.httpd.apache.org%3E url
- https://lists.apache.org/thread.html/r734a07156abf332d5ab27fb91d9d962cacfef4f3681e44056f064fa8@%3Ccvs.httpd.apache.org%3E url
- https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920@%3Ccvs.httpd.apache.org%3E url
- https://lists.apache.org/thread.html/rd65d8ba68ba17e7deedafbf5bb4899f2ae4dad781d21b931c2941ac3@%3Ccvs.httpd.apache.org%3E url
- https://lists.apache.org/thread.html/re895fc1736d25c8cf57e102c871613b8aeec9ea26fd8a44e7942b5ab@%3Ccvs.httpd.apache.org%3E url
- https://lists.apache.org/thread.html/rf2f0f3611f937cf6cfb3b4fe4a67f69885855126110e1e3f2fb2728e@%3Ccvs.httpd.apache.org%3E url
…and 12 more