The ap_proxy_ftp_handler function in modules/proxy/proxy_ftp.c in the mod_proxy_ftp module in the Apache HTTP Server 2.0.63 and 2.2.13 allows remote FTP servers to cause a denial of service (NULL pointer dereference and child process crash) via a malformed reply to an EPSV command.
CVSS Details
- CVSS 3.1 Base Score: 3.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Httpd | — | Upgrade to the latest version of Apache HTTPD | Apr 12, 2012 | Sep 8, 2009 |
| Apache Httpd 2_0_x Mod_proxy_ftp Dos | — | — | Aug 16, 2010 | Sep 8, 2009 |
| Centos_linux | — | Upgrade httpd-manualUpgrade mod_sslUpgrade httpdUpgrade httpd-suexecUpgrade httpd-devel | Dec 1, 2016 | Sep 8, 2009 |
| Debian | — | Upgrade apache2 | Jul 30, 2024 | Sep 8, 2009 |
| Oracle_linux | — | Upgrade httpd-develUpgrade httpdUpgrade mod_sslUpgrade httpd-manual | Oct 16, 2024 | Sep 8, 2009 |
| Suse | — | Upgrade apache2-manualUpgrade apache2-docUpgrade apache2-eventUpgrade apache2-utilsUpgrade apache2-preforkUpgrade apache2-workerUpgrade apache2-develUpgrade apache2Upgrade apache2-example-pages | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade apache2-commonUpgrade apache2.2-common | Nov 8, 2024 | Sep 8, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub