VDB
CVE-2004-0809
CVE-2004-0809
PUBLISHED
CVSS 5 MEDIUM
The mod_dav module in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (child process crash) via a certain sequence of LOCK requests for a location that allows WebDAV authoring access.
EPSS 14.02% · 94.5th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
14.02%
94.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| turbolinux | turbolinux_server | 10.0 |
| redhat | enterprise_linux | 3.0, 3.0, 3.0 |
| trustix | secure_linux | 2.0, 2.1 |
| turbolinux | turbolinux_home | |
| turbolinux | turbolinux_desktop | 10.0 |
| n/a | n/a | n/a |
| gentoo | linux | 1.4 |
| apache | http_server | 2.0.35 |
| debian | debian_linux | 3.0 |
| redhat | enterprise_linux_desktop | 3.0 |
| hp | secure_web_server_for_tru64 | 5.1_a, 5.8.1, 5.8.2 |
| hp | hp-ux | 11.11, 11.00, 11.23 |
| mandrakesoft | mandrake_linux | 10.0, 9.2, 9.2 |
Exploit Intelligence
- RHSA-2004:463 (circl)
- http://cvs.apache.org/viewcvs.cgi/httpd-2.0/modules/dav/fs/lock.c?r1=1.32&r2=1.33 (circl)
- 2004-0047 (circl)
- MDKSA-2004:096 (circl)
- DSA-558 (circl)
- GLSA-200409-21 (circl)
- oval:org.mitre.oval:def:9588 (circl)
- apache-moddav-lock-dos(17366) (circl)
- [httpd-cvs] 20190815 svn commit: r1048742 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html (circl)
- [httpd-cvs] 20190815 svn commit: r1048743 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html (circl)
…and 10 more exploits
Timeline
- Sep 16, 2004 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Oct 30, 2023 EPSS Score
- Dec 22, 2023 EPSS Score
References
- http://www.debian.org/security/2004/dsa-558 patch
- RHSA-2004:463 vendor-advisory
- http://cvs.apache.org/viewcvs.cgi/httpd-2.0/modules/dav/fs/lock.c?r1=1.32&r2=1.33 url
- 2004-0047 vendor-advisory
- MDKSA-2004:096 vendor-advisory
- GLSA-200409-21 vendor-advisory
- oval:org.mitre.oval:def:9588 vdb
- apache-moddav-lock-dos(17366) vdb
- [httpd-cvs] 20190815 svn commit: r1048742 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html mailing-list
- [httpd-cvs] 20190815 svn commit: r1048743 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html mailing-list
- [httpd-cvs] 20200401 svn commit: r1058586 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html mailing-list
- [httpd-cvs] 20200401 svn commit: r1058587 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html mailing-list
- [httpd-cvs] 20210330 svn commit: r1073139 [1/13] - in /websites/staging/httpd/trunk/content: ./ security/json/ mailing-list
- [httpd-cvs] 20210330 svn commit: r1073139 [3/13] - in /websites/staging/httpd/trunk/content: ./ security/json/ mailing-list
- [httpd-cvs] 20210330 svn commit: r1888194 [3/13] - /httpd/site/trunk/content/security/json/ mailing-list
- [httpd-cvs] 20210330 svn commit: r1073140 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/cvejsontohtml.py security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html mailing-list
- [httpd-cvs] 20210330 svn commit: r1073143 [2/3] - in /websites/staging/httpd/trunk/content: ./ security/ mailing-list
- [httpd-cvs] 20210330 svn commit: r1073149 [4/13] - in /websites/staging/httpd/trunk/content: ./ security/ security/json/ mailing-list
- [httpd-cvs] 20210330 svn commit: r1073149 [1/13] - in /websites/staging/httpd/trunk/content: ./ security/ security/json/ mailing-list
- [httpd-cvs] 20210606 svn commit: r1075470 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/json/CVE-2020-13938.json security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html mailing-list
…and 14 more