VDB
CVE-2004-2680
CVE-2004-2680
PUBLISHED
CVSS 5 MEDIUM
mod_python (libapache2-mod-python) 3.1.4 and earlier does not properly handle when output filters process more than 16384 bytes, which can cause filter.read to return portions of previously freed memory.
EPSS 10.51% · 93.4th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
10.51%
93.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| apache | mod_python | 0 |
Timeline
- Dec 31, 2004 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Oct 30, 2023 EPSS Score
- Dec 22, 2023 EPSS Score
References
- 24424 third-party-advisory
- USN-430-1 vendor-advisory
- [httpd-python-dev] 20040416 patch for filterobject.c mailing-list
- 20070307 rPSA-2007-0051-1 mod_python mailing-list
- [httpd-python-dev] 20040416 Re: possible bug in filter.write() mailing-list
- ADV-2007-0846 vdb
- [httpd-python-dev] 20040416 possible bug in filter.write() mailing-list
- https://launchpad.net/bugs/89308 url
- http://svn.apache.org/viewvc/httpd/mod_python/trunk/src/filterobject.c?r1=102649&r2=103561&pathrev=103561 url
- https://issues.rpath.com/browse/RPL-1105 url
- 24418 third-party-advisory
- 22849 vdb
- modpython-outputfilter-info-disclosure(14751) vdb
- https://nvd.nist.gov/vuln/detail/CVE-2004-2680 advisory
- http://mail-archives.apache.org/mod_mbox/httpd-python-dev/200404.mbox/%3c6DCA8C14-8FFA-11D8-8B4E-000A95B0D772@pixar.com%3e url
- http://mail-archives.apache.org/mod_mbox/httpd-python-dev/200404.mbox/%3cCD485B27-8F3E-11D8-934B-000A95B0D772@pixar.com%3e url
- http://mail-archives.apache.org/mod_mbox/httpd-python-dev/200404.mbox/%3cEB279100-9000-11D8-8B4E-000A95B0D772@pixar.com%3e url