MEDIUM · 5.0

CVE-2005-2970

Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances, allows remote attackers to cause a denial of service (memory consumption) via aborted connections, which prevents the m...

Vulnerability Description

Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances, allows remote attackers to cause a denial of service (memory consumption) via aborted connections, which prevents the memory for the transaction pool from being reused for other connections.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:N/A:P
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL

Affected Products

VendorProductVersions
ApacheHttp Server>= 2.0.36, < 2.0.55
CanonicalUbuntu Linux4.10
RedhatEnterprise Linux Desktop3.0
RedhatEnterprise Linux Server3.0
RedhatEnterprise Linux Workstation3.0
FedoraprojectFedora Core4

Related Weaknesses (CWE)

References

FAQ

What is CVE-2005-2970?

CVE-2005-2970 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances, allows remote attackers to cause a denial of service (memory consumption) via aborted connections, which prevents the m...

How severe is CVE-2005-2970?

CVE-2005-2970 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2005-2970?

Check the references section above for vendor advisories and patch information. Affected products include: Apache Http Server, Canonical Ubuntu Linux, Redhat Enterprise Linux Desktop, Redhat Enterprise Linux Server, Redhat Enterprise Linux Workstation.