CVE-2009-2699

The Solaris pollset feature in the Event Port backend in poll/unix/port.c in the Apache Portable Runtime (APR) library before 1.3.9, as used in the Apache HTTP Server before 2.2.14 and other products, does not properly handle errors, which allows remote attackers to cause a denial of service (daemon hang) via unspecified HTTP requests, related to the prefork and event MPMs.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 92%
VendorProductVersion
apachehttp_server
2.2.0 ≤
𝑥
< 2.2.14
apacheportable_runtime
𝑥
< 1.3.9
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
apr
bullseye (security)
1.7.0-6+deb11u2
fixed
bullseye
1.7.0-6+deb11u2
fixed
bookworm
1.7.2-3
fixed
sid
1.7.5-1
fixed
trixie
1.7.5-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
apr
jaunty
not-affected
intrepid
not-affected
hardy
not-affected
dapper
dne
References