The balancer_handler function in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6, when a threaded Multi-Processing Module is used, allows remote authenticated users to cause a denial of service (child process crash) via an invalid bb variable.
CVSS Details
- CVSS 3.1 Base Score: 4.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Httpd | — | Upgrade to the latest version of Apache HTTPD | Apr 12, 2012 | Jan 8, 2008 |
| Debian | — | Upgrade apache2 | Jul 30, 2024 | Jan 8, 2008 |
| Gentoo Linux | — | Upgrade www-servers/apache. | Oct 30, 2017 | Jan 8, 2008 |
| Oracle_linux | — | Upgrade mod_sslUpgrade httpd-manualUpgrade httpd-develUpgrade httpd | Oct 16, 2024 | Jan 8, 2008 |
| Suse | — | Upgrade apache2-utilsUpgrade apache2-preforkUpgrade apache2-docUpgrade apache2-manualUpgrade apache2-eventUpgrade apache2-develUpgrade apache2Upgrade apache2-workerUpgrade apache2-example-pages | Feb 17, 2015 | Jul 9, 2013 |
| Ubuntu | — | Upgrade apache2-mpm-preforkUpgrade apache2-mpm-workerUpgrade apache2-mpm-perchildUpgrade apache2-mpm-event | Nov 8, 2024 | Jan 8, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub