HIGH · 10.0

CVE-2004-0492

Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negat...

Vulnerability Description

Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes a large amount of data to be copied.

CVSS Score

10.0

HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
ApacheHttp Server1.3.26
HpVirtualvault11.0.4
HpWebproxy2.0
IbmHttp Server1.3.26
SgiPropack2.4
HpVvos11.04
OpenbsdOpenbsdAll versions

References

FAQ

What is CVE-2004-0492?

CVE-2004-0492 is a vulnerability with a CVSS score of 10.0 (HIGH). Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negat...

How severe is CVE-2004-0492?

CVE-2004-0492 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2004-0492?

Check the references section above for vendor advisories and patch information. Affected products include: Apache Http Server, Hp Virtualvault, Hp Webproxy, Ibm Http Server, Sgi Propack.