vendor:
mod_ssl
by:
Unknown
7.5
CVSS
HIGH
Remote Denial of Service
Unknown
CWE
Product Name: mod_ssl
Affected Version From: Apache 2.0.50
Affected Version To: Unknown
Patch Exists: NO
Related CWE: Unknown
CPE: Unknown
Platforms Tested: Unknown
Unknown
Remote Denial of Service Vulnerability in Apache 2.x mod_ssl
The vulnerability exists in the 'char_buffer_read' function of the 'ssl_engine_io.c' file in Apache 2.x mod_ssl. It allows remote attackers to crash the server by sending a specific URI.
Mitigation:
Unknown