CVE-2009-3094

Advisory lineage Upstream: 0 Downstream: 8
Modified
Published: 08 Sept 2009, 18:00
Last modified:07 Aug 2024, 06:14

Vulnerability Summary

Overall Risk (default)
low
11/100
CVSS Score
2.6 LOW
v2.0 (nvd)
EPSS Score
2.83% LOW
3% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

08 Sept 2009, 18:00
Published
Vulnerability first disclosed
07 Aug 2024, 06:14
Last Modified
Vulnerability information updated

Description

The ap_proxy_ftp_handler function in modules/proxy/proxy_ftp.c in the mod_proxy_ftp module in the Apache HTTP Server 2.0.63 and 2.2.13 allows remote FTP servers to cause a denial of service (NULL pointer dereference and child process crash) via a malformed reply to an EPSV command.

CVSS Metrics

  • v2.0LOWScore: 2.6AV:N/AC:H/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 2.83% Percentile: 86%

Techniques & Countermeasures

  • CWE-476NULL Pointer Dereference

    The product dereferences a pointer that it expects to be valid but is NULL.

Affected Systems

  • UnknownHTTP Server

    ≥ 2.0.35, < 2.0.64 | ≥ 2.2.0, < 2.2.14

  • debiandebian_linux

    4.0 | 5.0

  • fedoraprojectfedora

    10 | 12

References (40)