CVE
- Id
- 8920
- CVE No.
- CVE-2004-0492
- Status
- Candidate
- Description
- Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes a large amount of data to be copied.
- Phase
- Assigned (20040527)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
| Id | CVE Id | CVE No. | Reference | Actions |
|---|---|---|---|---|
| 57051 | 8920 | CVE-2004-0492 | FULLDISC:20040610 Buffer overflow in apache mod_proxy,yet still apache much better than windows | View |
| 57052 | 8920 | CVE-2004-0492 | URL:http://seclists.org/lists/fulldisclosure/2004/Jun/0296.html | View |
| 57053 | 8920 | CVE-2004-0492 | MISC:http://www.guninski.com/modproxy1.html | View |
| 57054 | 8920 | CVE-2004-0492 | BUGTRAQ:20040611 [OpenPKG-SA-2004.029] OpenPKG Security Advisory (apache) | View |
| 57055 | 8920 | CVE-2004-0492 | URL:http://marc.info/?l=bugtraq&m=108711172710140&w=2 | View |
| 57056 | 8920 | CVE-2004-0492 | DEBIAN:DSA-525 | View |
| 57057 | 8920 | CVE-2004-0492 | URL:http://www.debian.org/security/2004/dsa-525 | View |
| 57058 | 8920 | CVE-2004-0492 | FEDORA:FLSA:1737 | View |
| 57059 | 8920 | CVE-2004-0492 | URL:https://bugzilla.fedora.us/show_bug.cgi?id=1737 | View |
| 57060 | 8920 | CVE-2004-0492 | HP:HPSBOV02683 | View |
| 57061 | 8920 | CVE-2004-0492 | URL:http://marc.info/?l=bugtraq&m=130497311408250&w=2 | View |
| 57062 | 8920 | CVE-2004-0492 | HP:SSRT090208 | View |
| 57063 | 8920 | CVE-2004-0492 | URL:http://marc.info/?l=bugtraq&m=130497311408250&w=2 | View |
| 57064 | 8920 | CVE-2004-0492 | MANDRAKE:MDKSA-2004:065 | View |
| 57065 | 8920 | CVE-2004-0492 | URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:065 | View |
| 57066 | 8920 | CVE-2004-0492 | REDHAT:RHSA-2004:245 | View |
| 57067 | 8920 | CVE-2004-0492 | URL:http://rhn.redhat.com/errata/RHSA-2004-245.html | View |
| 57068 | 8920 | CVE-2004-0492 | SGI:20040605-01-U | View |
| 57069 | 8920 | CVE-2004-0492 | URL:ftp://patches.sgi.com/support/free/security/advisories/20040605-01-U.asc | View |
| 57070 | 8920 | CVE-2004-0492 | SUNALERT:57628 | View |
| 57071 | 8920 | CVE-2004-0492 | URL:http://sunsolve.sun.com/search/document.do?assetkey=1-26-57628-1 | View |
| 57072 | 8920 | CVE-2004-0492 | SUNALERT:101555 | View |
| 57073 | 8920 | CVE-2004-0492 | URL:http://sunsolve.sun.com/search/document.do?assetkey=1-26-101555-1 | View |
| 57074 | 8920 | CVE-2004-0492 | SUNALERT:101841 | View |
| 57075 | 8920 | CVE-2004-0492 | URL:http://sunsolve.sun.com/search/document.do?assetkey=1-26-101841-1 | View |
| 57076 | 8920 | CVE-2004-0492 | CERT-VN:VU#541310 | View |
| 57077 | 8920 | CVE-2004-0492 | URL:http://www.kb.cert.org/vuls/id/541310 | View |
| 57078 | 8920 | CVE-2004-0492 | OVAL:oval:org.mitre.oval:def:4863 | View |
| 57079 | 8920 | CVE-2004-0492 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4863 | View |
| 57080 | 8920 | CVE-2004-0492 | OVAL:oval:org.mitre.oval:def:100112 | View |
| 57081 | 8920 | CVE-2004-0492 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100112 | View |
| 57082 | 8920 | CVE-2004-0492 | SECUNIA:11841 | View |
| 57083 | 8920 | CVE-2004-0492 | URL:http://secunia.com/advisories/11841 | View |
| 57084 | 8920 | CVE-2004-0492 | XF:apache-modproxy-contentlength-bo(16387) | View |
Related JVN
| Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 62901 | JVNDB-2004-000243 | Apache HTTP Server の ap_get_mime_headers_core() 関数におけるサービス運用妨害 (DoS) の脆弱性 | Apache HTTP Server には、ap_get_mime_headers_core() 関数において取り扱うリクエストヘッダの長さのチェックが不適切である脆弱性が存在します。 | CVE-2004-0493 | 8920 | 6.4 | http://jvndb.jvn.jp/ja/contents/2004/JVNDB-2004-000243.html | View |