CVE-2008-2364

Description

The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP servers to cause a denial of service (memory consumption) via a large number of interim responses.

Risk Information

Base Score
7.5
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
2.213

Associated Vulnerability

VulnerabilityOS Platform
Update Apache to version 2.2.8Windows
Vulnerabilities CVE-2008-2364 are fixed in Apache 2.2.9Windows
Multiple vulnerabilities are fixed in Apache 2.0.64Windows
Multiple vulnerabilities are affected in Oracle HTTP Server 5.0Windows
Update Apache to version 2.2.8 (For Linux)Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234