Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes a large amount of data to be copied.
2004-08-06T04:00:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 10.0 (HIGH)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | apache | http_server | 1.3.26 | Yes |
Application | apache | http_server | 1.3.27 | Yes |
Application | apache | http_server | 1.3.28 | Yes |
Application | apache | http_server | 1.3.29 | Yes |
Application | apache | http_server | 1.3.31 | Yes |
Application | hp | virtualvault | 11.0.4 | Yes |
Application | hp | webproxy | 2.0 | Yes |
Application | hp | webproxy | 2.1 | Yes |
Application | ibm | http_server | 1.3.26 | Yes |
Application | ibm | http_server | 1.3.26.1 | Yes |
Application | ibm | http_server | 1.3.26.2 | Yes |
Application | ibm | http_server | 1.3.28 | Yes |
Application | sgi | propack | 2.4 | Yes |
Operating System | hp | vvos | 11.04 | Yes |
Operating System | openbsd | openbsd | * | Yes |
Operating System | openbsd | openbsd | 3.4 | Yes |
Operating System | openbsd | openbsd | 3.5 | Yes |