CVE Database
/

CVE-2009-1891

Back to search

CVE-2009-1891

Published: Jul 10, 2009

Modified: Aug 7, 2024

PUBLISHED

Description

The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is closed, which allows remote attackers to cause a denial of service (CPU consumption).

VendorProductVersions

n/a

n/a

affected
n/a

References

[apache-httpd-dev] 20090628 mod_deflate DoS
mailing-list
x_refsource_MLIST
FEDORA-2009-8812
vendor-advisory
x_refsource_FEDORA
SUSE-SA:2009:050
vendor-advisory
x_refsource_SUSE
35781
third-party-advisory
x_refsource_SECUNIA
PK99480
vendor-advisory
x_refsource_AIXAPAR
oval:org.mitre.oval:def:12361
vdb-entry
signature
x_refsource_OVAL
MDVSA-2009:149
vendor-advisory
x_refsource_MANDRIVA
PK91361
vendor-advisory
x_refsource_AIXAPAR
SSRT090208
vendor-advisory
x_refsource_HP
RHSA-2009:1156
vendor-advisory
x_refsource_REDHAT
35865
third-party-advisory
x_refsource_SECUNIA
ADV-2009-1841
vdb-entry
x_refsource_VUPEN
37152
third-party-advisory
x_refsource_SECUNIA
1022529
vdb-entry
x_refsource_SECTRACK
DSA-1834
vendor-advisory
x_refsource_DEBIAN
20091113 rPSA-2009-0142-2 httpd mod_ssl
mailing-list
x_refsource_BUGTRAQ
oval:org.mitre.oval:def:8632
vdb-entry
signature
x_refsource_OVAL
HPSBUX02612
vendor-advisory
x_refsource_HP
GLSA-200907-04
vendor-advisory
x_refsource_GENTOO
HPSBOV02683
vendor-advisory
x_refsource_HP
RHSA-2009:1148
vendor-advisory
x_refsource_REDHAT
oval:org.mitre.oval:def:9248
vdb-entry
signature
x_refsource_OVAL
USN-802-1
vendor-advisory
x_refsource_UBUNTU
37221
third-party-advisory
x_refsource_SECUNIA
ADV-2009-3184
vdb-entry
x_refsource_VUPEN
SSRT100345
vendor-advisory
x_refsource_HP
35793
third-party-advisory
x_refsource_SECUNIA
APPLE-SA-2009-11-09-1
vendor-advisory
x_refsource_APPLE
35721
third-party-advisory
x_refsource_SECUNIA
55782
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now