CVE-2012-3526

EUVD-2012-3481
The reverse proxy add forward module (mod_rpaf) 0.5 and 0.6 for the Apache HTTP Server allows remote attackers to cause a denial of service (server or application crash) via multiple X-Forwarded-For headers in a request.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:N/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 83%
Affected Products (NVD)
VendorProductVersion
thomas_eibnermod_rpaf
0.5
thomas_eibnermod_rpaf
0.6
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libapache2-mod-rpaf
bookworm
0.6-14
fixed
bullseye
0.6-13
fixed
sid
0.6-14
fixed
trixie
0.6-14
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libapache2-mod-rpaf
hardy
Fixed 0.5-3+squeeze1build0.8.04.1
released
lucid
Fixed 0.5-3+squeeze1build0.10.04.1
released
natty
Fixed 0.5-3+squeeze1build0.11.04.1
released
oneiric
Fixed 0.5-3+squeeze1build0.11.10.1
released
precise
not-affected