The balancer_handler function in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6, when a threaded Multi-Processing Module is used, allows remote authenticated users to cause a denial of service (child process crash) via an invalid bb variable.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Http_server | Apache | - (including) | - (including) |
Http_server | Apache | 2.2 (including) | 2.2 (including) |
Http_server | Apache | 2.2.1 (including) | 2.2.1 (including) |
Http_server | Apache | 2.2.2 (including) | 2.2.2 (including) |
Http_server | Apache | 2.2.3 (including) | 2.2.3 (including) |
Http_server | Apache | 2.2.4 (including) | 2.2.4 (including) |
Http_server | Apache | 2.2.6 (including) | 2.2.6 (including) |
Red Hat Enterprise Linux 5 | RedHat | httpd-0:2.2.3-11.el5_1.3 | * |
Apache2 | Ubuntu | dapper | * |
Apache2 | Ubuntu | edgy | * |
Apache2 | Ubuntu | feisty | * |
Apache2 | Ubuntu | gutsy | * |