You are viewing a plain text version of this content. The canonical link for it is here.
Posted to cvs@httpd.apache.org by mj...@apache.org on 2012/10/30 16:21:15 UTC

svn commit: r1403738 - /httpd/site/trunk/content/security/vulnerabilities-httpd.xml

Author: mjc
Date: Tue Oct 30 15:21:15 2012
New Revision: 1403738

URL: http://svn.apache.org/viewvc?rev=1403738&view=rev
Log:
Quick document of CVE-2012-4557

Modified:
    httpd/site/trunk/content/security/vulnerabilities-httpd.xml

Modified: httpd/site/trunk/content/security/vulnerabilities-httpd.xml
URL: http://svn.apache.org/viewvc/httpd/site/trunk/content/security/vulnerabilities-httpd.xml?rev=1403738&r1=1403737&r2=1403738&view=diff
==============================================================================
--- httpd/site/trunk/content/security/vulnerabilities-httpd.xml (original)
+++ httpd/site/trunk/content/security/vulnerabilities-httpd.xml Tue Oct 30 15:21:15 2012
@@ -110,6 +110,31 @@ administrator runs apachectl from an unt
 <affects prod="httpd" version="2.4.1"/>
 </issue>
 
+<issue fixed="2.2.22" reported="20121011" public="20120104" released="20120131">
+<cve name="CVE-2011-4557"/>
+<severity level="4">low</severity>
+<title>mod_proxy_ajp remote DoS</title>
+<description><p>
+
+A flaw was found when mod_proxy_ajp connects to a backend server that
+takes too long to respond.  Given a specific configuration, a remote
+attacker could send certain requests, putting a backend server into an
+error state until the retry timeout expired.  This could lead to a
+temporary denial of service.</p>
+
+</description>
+<affects prod="httpd" version="2.2.21"/>
+<affects prod="httpd" version="2.2.20"/>
+<affects prod="httpd" version="2.2.19"/>
+<affects prod="httpd" version="2.2.18"/>
+<affects prod="httpd" version="2.2.17"/>
+<affects prod="httpd" version="2.2.16"/>
+<affects prod="httpd" version="2.2.15"/>
+<affects prod="httpd" version="2.2.14"/>
+<affects prod="httpd" version="2.2.13"/>
+<affects prod="httpd" version="2.2.12"/>
+</issue>
+
 <issue fixed="2.2.22" reported="20111004" public="20111102" released="20120131">
 <cve name="CVE-2011-3607"/>
 <severity level="4">low</severity>