The ap_proxy_ftp_handler function in modules/proxy/proxy_ftp.c in the mod_proxy_ftp module in the Apache HTTP Server 2.0.63 and 2.2.13 allows remote FTP servers to cause a denial of service (NULL pointer dereference and child process crash) via a malformed reply to an EPSV command.
2009-09-08T18:30:00.657
2025-04-09T00:30:58.490
Deferred
CVSSv2: 2.6 (LOW)
AV:N/AC:H/Au:N/C:N/I:N/A:P
4.9
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | apache | http_server | < 2.0.64 | Yes |
Application | apache | http_server | < 2.2.14 | Yes |
Operating System | fedoraproject | fedora | 10 | Yes |
Operating System | fedoraproject | fedora | 12 | Yes |
Operating System | debian | debian_linux | 4.0 | Yes |
Operating System | debian | debian_linux | 5.0 | Yes |