CVE-2005-2970
MEDIUM severity · CVSS 5 · Resource exhaustion
5CVSS MEDIUM
Summary
Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances, allows remote attackers to cause a denial of service (memory consumption) via aborted connections, which prevents the memory for the transaction pool from being reused for other connections.
Impact & exploitability
Attack vectorNetwork
Attack complexityLow
Privileges required—
User interaction—
Confidentiality impactNone
Integrity impactNone
Availability impact—
Exploit probability (EPSS)14%
AV:N/AC:L/Au:N/C:N/I:N/A:P
Affected products we track (1)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Additional information
- NVD record
- http://mail-archives.apache.org/mod_mbox/httpd-cvs/200509.mbox/%3C20051001110218.40692.qmail%40minotaur.apache.org%3E
- http://rhn.redhat.com/errata/RHSA-2006-0159.htmlAdvisory
- http://secunia.com/advisories/16559
- http://secunia.com/advisories/17923
- http://secunia.com/advisories/18161
- http://secunia.com/advisories/18333
- http://secunia.com/advisories/18585
- http://securitytracker.com/id?1015093Advisory