The reverse proxy add forward module (mod_rpaf) 0.5 and 0.6 for the Apache HTTP Server allows remote attackers to cause a denial of service (server or application crash) via multiple X-Forwarded-For headers in a request.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mod_rpaf | Thomas_eibner | 0.5 (including) | 0.5 (including) |
Mod_rpaf | Thomas_eibner | 0.6 (including) | 0.6 (including) |
Libapache2-mod-rpaf | Ubuntu | hardy | * |
Libapache2-mod-rpaf | Ubuntu | lucid | * |
Libapache2-mod-rpaf | Ubuntu | natty | * |
Libapache2-mod-rpaf | Ubuntu | oneiric | * |
Libapache2-mod-rpaf | Ubuntu | upstream | * |