Vulnerability Description
Memory leak in the apr_brigade_split_line function in buckets/apr_brigade.c in the Apache Portable Runtime Utility library (aka APR-util) before 1.3.10, as used in the mod_reqtimeout module in the Apache HTTP Server and other software, allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors related to the destruction of an APR bucket.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Apr-Util | <= 1.3.9 |
| Apache | Http Server | >= 2.0.35, < 2.0.64 |
Related Weaknesses (CWE)
References
- http://blogs.sun.com/security/entry/cve_2010_1623_memory_leakMailing ListThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049885.htMailing ListThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049939.htMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00011.htmlMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=130168502603566&w=2Mailing ListThird Party Advisory
- http://secunia.com/advisories/41701Vendor Advisory
- http://secunia.com/advisories/42015Vendor Advisory
- http://secunia.com/advisories/42361Vendor Advisory
- http://secunia.com/advisories/42367Vendor Advisory
- http://secunia.com/advisories/42403Vendor Advisory
- http://secunia.com/advisories/42537Vendor Advisory
- http://secunia.com/advisories/43211Vendor Advisory
- http://secunia.com/advisories/43285Vendor Advisory
- http://security-tracker.debian.org/tracker/CVE-2010-1623Third Party Advisory
- http://slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackwareMailing ListThird Party Advisory
FAQ
What is CVE-2010-1623?
CVE-2010-1623 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Memory leak in the apr_brigade_split_line function in buckets/apr_brigade.c in the Apache Portable Runtime Utility library (aka APR-util) before 1.3.10, as used in the mod_reqtimeout module in the Apa...
How severe is CVE-2010-1623?
CVE-2010-1623 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-1623?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Apr-Util, Apache Http Server.