vendor:
APR
by:
SecurityFocus
7,5
CVSS
HIGH
Denial-of-Service
400
CWE
Product Name: APR
Affected Version From: 1.4.2
Affected Version To: 1.4.3
Patch Exists: YES
Related CWE: CVE-2012-0022
CPE: a:apache:apr:1.4.2
Metasploit:
https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2012-0076/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2012-0474/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2012-0475/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2012-0074/, https://www.rapid7.com/db/vulnerabilities/hpux-cve-2012-0022/, https://www.rapid7.com/db/vulnerabilities/freebsd-vid-7f5ccb1d-439b-11e1-bc16-0023ae8e59f0/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2012-0022/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2012-0022/, https://www.rapid7.com/db/vulnerabilities/vmsa-2012-0005-cve-2012-0022/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2012-0022/, https://www.rapid7.com/db/vulnerabilities/oracle-solaris-cve-2012-0022/, https://www.rapid7.com/db/vulnerabilities/apache-tomcat-cve-2012-0022/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2012-0680/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2012-0682/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2012
Apache APR Denial-of-Service Vulnerability
Apache APR is prone to a denial-of-service vulnerability. An attacker can exploit this issue by sending specially crafted forms in HTTP POST requests. Successful exploits will cause the application to crash, denying service to legitimate users.
Mitigation:
Upgrade to the latest version of Apache APR.