httpd-cvs mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
Subject svn commit: r1403738 - /httpd/site/trunk/content/security/vulnerabilities-httpd.xml
Date Tue, 30 Oct 2012 15:21:15 GMT
Author: mjc
Date: Tue Oct 30 15:21:15 2012
New Revision: 1403738

Quick document of CVE-2012-4557


Modified: httpd/site/trunk/content/security/vulnerabilities-httpd.xml
--- httpd/site/trunk/content/security/vulnerabilities-httpd.xml (original)
+++ httpd/site/trunk/content/security/vulnerabilities-httpd.xml Tue Oct 30 15:21:15 2012
@@ -110,6 +110,31 @@ administrator runs apachectl from an unt
 <affects prod="httpd" version="2.4.1"/>
+<issue fixed="2.2.22" reported="20121011" public="20120104" released="20120131">
+<cve name="CVE-2011-4557"/>
+<severity level="4">low</severity>
+<title>mod_proxy_ajp remote DoS</title>
+A flaw was found when mod_proxy_ajp connects to a backend server that
+takes too long to respond.  Given a specific configuration, a remote
+attacker could send certain requests, putting a backend server into an
+error state until the retry timeout expired.  This could lead to a
+temporary denial of service.</p>
+<affects prod="httpd" version="2.2.21"/>
+<affects prod="httpd" version="2.2.20"/>
+<affects prod="httpd" version="2.2.19"/>
+<affects prod="httpd" version="2.2.18"/>
+<affects prod="httpd" version="2.2.17"/>
+<affects prod="httpd" version="2.2.16"/>
+<affects prod="httpd" version="2.2.15"/>
+<affects prod="httpd" version="2.2.14"/>
+<affects prod="httpd" version="2.2.13"/>
+<affects prod="httpd" version="2.2.12"/>
 <issue fixed="2.2.22" reported="20111004" public="20111102" released="20120131">
 <cve name="CVE-2011-3607"/>
 <severity level="4">low</severity>

View raw message