← Back to CVE List
Vulnerability Intelligence Report

CVE-2004-0492

Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes a large amount of data to be copied.

No Active Exploit Signals
CVSS Base Score
10.0
HIGH
EPSS Probability:33.64%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Affected Products & Versions

Vendor Product Affected Versions
apache http_server 1.3.26, 1.3.27, 1.3.28, 1.3.29, 1.3.31
hp virtualvault 11.0.4
hp webproxy 2.0, 2.1
ibm http_server 1.3.26, 1.3.26.1, 1.3.26.2, 1.3.28
sgi propack 2.4
hp vvos 11.04
openbsd openbsd 3.4, 3.5

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
33.639%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2004-05-27T00:00:00
Published2004-06-23T04:00:00
Patch Date2004-06-10
Last Updated2024-08-08T00:17:15

LINK COPIED TO CLIPBOARD