CVE-2009-1890
highCVSS v3 Base Score
7.1
AV:N/AC:M/Au:N/C:N/I:N/A:C
EPSS Score
37.9%
Exploitation probability in 30 days
Top 3% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
M
Confidentiality
None
Integrity
None
Availability
C
Vulnerability Report
Generated by CyberWatcher
Description
The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which allows remote attackers to cause a denial of service (CPU consumption) via crafted requests.
CWE
CWE-400Affected Products
apache http serverfedoraproject fedoradebian debian linuxcanonical ubuntu linuxredhat enterprise linux desktopredhat enterprise linux eusredhat enterprise linux serverredhat enterprise linux server ausredhat enterprise linux workstation