FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2004-0942

This CVE name corresponds to:

Entered Topic
2004-11-10 apache2 multiple space header denial-of-service vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2004-0942
Phase Assigned(20041012)

Description

Apache webserver 2.0.52 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an HTTP GET request with a MIME header containing multiple lines with a large number of space characters.

References

Source Reference
FULLDISC 20041101 DoS in Apache 2.0.52 ?
CONFIRM http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm
APPLE APPLE-SA-2005-08-15
APPLE APPLE-SA-2005-08-17
HP SSRT4876
HP HPSBUX01123
MANDRAKE MDKSA-2004:135
REDHAT RHSA-2004:562
SUNALERT 102198
TRUSTIX 2004-0061
OVAL oval:org.mitre.oval:def:10962
VUPEN ADV-2006-0789
SECUNIA 19072
XF apache-http-get-dos(17930)