← Back

CVE-2004-0492

nvd nist
Published: Aug 6, 2004Modified: Apr 16, 2026

JSON object

Loading...
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD

Description

Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes a large amount of data to be copied.

Affected (17)

Products: Apache: Http Server · Hp: Virtualvault, Webproxy, Vvos · Ibm: Http Server · +2 more
Show all products
1 product
Http Server
3 products
Virtualvault
Webproxy
Vvos
1 product
Http Server
1 product
Propack
1 product
Openbsd
Configuration A
13 vulnerable
Vulnerable SoftwareAffected Versions
Apache
Version 1.3.26
Version 1.3.27
Version 1.3.28
Version 1.3.29
Version 1.3.31
Version 11.0.4
Hp
Version 2.0
Version 2.1
Ibm
Version 1.3.26.1
Version 1.3.26.2
Version 1.3.26
Version 1.3.28
Version 2.4
Configuration B
4 vulnerable
Vulnerable SoftwareAffected Versions
Version 11.04
Openbsd
All versions
Version 3.4
Version 3.5

References (48)

ftp://patches.sgi.com/support/free/security/advisories/20040605-01-U.asc (unsafe URL)
Source: cve@mitre.org
Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
US Government Resource
ftp://patches.sgi.com/support/free/security/advisories/20040605-01-U.asc (unsafe URL)
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.