VDB
CVE-2005-2970
CVE-2005-2970
PUBLISHED
CVSS 5 MEDIUM
Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances, allows remote attackers to cause a denial of service (memory consumption) via aborted connections, which prevents the memory for the transaction pool from being reused for other connections.
EPSS 14.19% · 96.4th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
14.19%
96.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| canonical | ubuntu_linux | 5.04, 5.10, 4.10 |
| apache | http_server | 2.0.36 |
| redhat | enterprise_linux_server | 4.0, 3.0 |
| redhat | enterprise_linux_desktop | 3.0, 4.0 |
| redhat | enterprise_linux_workstation | 3.0, 4.0 |
| n/a | n/a | * |
| fedoraproject | fedora_core | 4 |
Timeline
- Oct 25, 2005 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Oct 31, 2023 EPSS Score
- Dec 23, 2023 EPSS Score
References
- http://mail-archives.apache.org/mod_mbox/httpd-cvs/200509.mbox/%3C20051001110218.40692.qmail%40minotaur.apache.org%3E url
- 18161 third-party-advisory
- [httpd-cvs] 20210330 svn commit: r1073139 [4/13] - in /websites/staging/httpd/trunk/content: ./ security/json/ mailing-list
- 1015093 vdb
- RHSA-2006:0159 vendor-advisory
- FEDORA-2006-052 vendor-advisory
- 16559 third-party-advisory
- [httpd-cvs] 20190815 svn commit: r1048743 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html mailing-list
- [httpd-cvs] 20200401 svn commit: r1058587 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html mailing-list
- [httpd-cvs] 20210330 svn commit: r1073143 [2/3] - in /websites/staging/httpd/trunk/content: ./ security/ mailing-list
- [httpd-cvs] 20210330 svn commit: r1073149 [5/13] - in /websites/staging/httpd/trunk/content: ./ security/ security/json/ mailing-list
- http://secunia.com/advisories/18585 technical
- http://svn.apache.org/viewcvs?rev=292949&view=rev advisory
- https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E technical
- http://secunia.com/advisories/18333 technical
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:233 technical
- http://www.securityfocus.com/archive/1/425399/100/0/threaded advisory
- https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E technical
- https://lists.apache.org/thread.html/r652fc951306cdeca5a276e2021a34878a76695a9f3cfb6490b4a6840%40%3Ccvs.httpd.apache.org%3E technical
- https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E technical
…and 23 more