Back

HIGH

httpd: mod_proxy reverse proxy DoS (infinite loop)

Published Jul 5, 2009

Description

The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which allows remote attackers to cause a denial of service (CPU consumption) via crafted requests.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (53)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jul 5, 2009
Updated Aug 7, 2024
Reserved Jun 2, 2009
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Jul 2, 2009