Rapid7 Vulnerability & Exploit Database

Apache HTTPD: Multiple header Denial of Service vulnerability (CVE-1999-1199)

Back to Search

Apache HTTPD: Multiple header Denial of Service vulnerability (CVE-1999-1199)

Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
08/07/1998
Created
07/25/2018
Added
04/12/2012
Modified
01/13/2022

Description

A serious problem exists when a client sends a large number of headers with the same header name. Apache uses up memory faster than the amount of memory required to simply store the received data itself. That is, memory use increases faster and faster as more headers are received, rather than increasing at a constant rate. This makes a denial of service attack based on this method more effective than methods which cause Apache to use memory at a constant rate, since the attacker has to send less data.

Solution(s)

  • apache-httpd-upgrade-1_3_2

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;