Back

MEDIUM

httpd: Apache Slowloris denial of service

Published Dec 27, 2011

Description

The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris, related to the lack of the mod_reqtimeout module in versions before 2.2.15.

Affected products

Remediation

Red Hat statement

This issue affects the version of httpd package as shipped with Red Hat Enterprise Linux 4. This issue is mitigated by the use of mod_reqtimeout module shipped with the httpd package in Red Hat Enterprise Linux 5 and 6.

Metrics

Weaknesses (1)

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 27, 2011
Updated Aug 7, 2024
Reserved Dec 27, 2011
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Jun 17, 2009