CVE-2009-1890
Detail
Modified After Enrichment
This CVE record has been updated after NVD enrichment efforts were completed. Enrichment data supplied by the NVD may require amendment due to these changes.
Description
The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which allows remote attackers to cause a denial of service (CPU consumption) via crafted requests.
Metrics
CVSS Version 4.0
CVSS Version 3.x
CVSS Version 2.0
NVD enrichment efforts reference publicly available information to associate
vector strings. CVSS information contributed by other sources is also
displayed.
CVSS 4.0 Severity and Vector Strings:
NVD assessment
not yet provided.
CVSS 3.x Severity and Vector Strings:
NVD assessment
not yet provided.
CVSS 2.0 Severity and Vector Strings:
Vector:
(AV:N/AC:M/Au:N/C:N/I:N/A:C)
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace.
We have provided these links to other web sites because they
may have information that would be of interest to you. No
inferences should be drawn on account of other sites being
referenced, or not, from this page. There may be other web
sites that are more appropriate for your purpose. NIST does
not necessarily endorse the views expressed, or concur with
the facts presented on these sites. Further, NIST does not
endorse any commercial products that may be mentioned on
these sites. Please address comments about this page to [email protected] .
URL
Source(s)
Tag(s)
http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html
CVE, Inc., Red Hat
Broken Link
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00006.html
CVE, Inc., Red Hat
Mailing List
Third Party Advisory
http://marc.info/?l=bugtraq&m=129190899612998&w=2
CVE, Inc., Red Hat
Issue Tracking
Mailing List
Third Party Advisory
http://osvdb.org/55553
CVE, Inc., Red Hat
Broken Link
http://secunia.com/advisories/35691
CVE, Inc., Red Hat
Not Applicable
Vendor Advisory
http://secunia.com/advisories/35721
CVE, Inc., Red Hat
Not Applicable
http://secunia.com/advisories/35793
CVE, Inc., Red Hat
Not Applicable
http://secunia.com/advisories/35865
CVE, Inc., Red Hat
Not Applicable
http://secunia.com/advisories/37152
CVE, Inc., Red Hat
Not Applicable
Vendor Advisory
http://secunia.com/advisories/37221
CVE, Inc., Red Hat
Not Applicable
Vendor Advisory
http://security.gentoo.org/glsa/glsa-200907-04.xml
CVE, Inc., Red Hat
Third Party Advisory
http://support.apple.com/kb/HT3937
CVE, Inc., Red Hat
Broken Link
http://svn.apache.org/viewvc/httpd/httpd/trunk/CHANGES?r1=790587&r2=790586&pathrev=790587
CVE, Inc., Red Hat
Patch
Vendor Advisory
http://svn.apache.org/viewvc/httpd/httpd/trunk/CHANGES?revision=790587
CVE, Inc., Red Hat
Vendor Advisory
http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/proxy/mod_proxy_http.c?r1=790587&r2=790586&pathrev=790587
CVE, Inc., Red Hat
Patch
Vendor Advisory
http://svn.apache.org/viewvc?view=rev&revision=790587
CVE, Inc., Red Hat
Vendor Advisory
http://wiki.rpath.com/Advisories:rPSA-2009-0142
CVE, Inc., Red Hat
Broken Link
http://www-01.ibm.com/support/docview.wss?uid=swg1PK91259
CVE, Inc., Red Hat
Third Party Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg1PK99480
CVE, Inc., Red Hat
Third Party Advisory
http://www.debian.org/security/2009/dsa-1834
CVE, Inc., Red Hat
Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2009:149
CVE, Inc., Red Hat
Broken Link
http://www.mandriva.com/security/advisories?name=MDVSA-2013:150
CVE, Inc., Red Hat
Broken Link
http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html
CVE, Inc., Red Hat
Third Party Advisory
http://www.redhat.com/support/errata/RHSA-2009-1156.html
CVE, Inc., Red Hat
Third Party Advisory
http://www.securityfocus.com/archive/1/507852/100/0/threaded
CVE, Inc., Red Hat
Third Party Advisory
VDB Entry
http://www.securityfocus.com/archive/1/507857/100/0/threaded
CVE, Inc., Red Hat
Third Party Advisory
VDB Entry
http://www.securityfocus.com/bid/35565
CVE, Inc., Red Hat
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id?1022509
CVE, Inc., Red Hat
Broken Link
Third Party Advisory
VDB Entry
http://www.ubuntu.com/usn/USN-802-1
CVE, Inc., Red Hat
Third Party Advisory
http://www.vupen.com/english/advisories/2009/3184
CVE, Inc., Red Hat
Permissions Required
Vendor Advisory
https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E
CVE, Inc., Red Hat
https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E
CVE, Inc., Red Hat
https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E
CVE, Inc., Red Hat
https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E
CVE, Inc., Red Hat
https://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3E
CVE, Inc., Red Hat
https://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3E
CVE, Inc., Red Hat
https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E
CVE, Inc., Red Hat
https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E
CVE, Inc., Red Hat
https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E
CVE, Inc., Red Hat
https://lists.apache.org/thread.html/rb33be0aa9bd8cac9536293e3821dcd4cf8180ad95a8036eedd46365e%40%3Cusers.mina.apache.org%3E
CVE, Inc., Red Hat
https://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8%40%3Ccvs.httpd.apache.org%3E
CVE, Inc., Red Hat
https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E
CVE, Inc., Red Hat
https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E
CVE, Inc., Red Hat
https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E
CVE, Inc., Red Hat
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12330
CVE, Inc., Red Hat
Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8616
CVE, Inc., Red Hat
Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9403
CVE, Inc., Red Hat
Third Party Advisory
https://rhn.redhat.com/errata/RHSA-2009-1148.html
CVE, Inc., Red Hat
Third Party Advisory
https://www.redhat.com/archives/fedora-package-announce/2009-August/msg01363.html
CVE, Inc., Red Hat
Third Party Advisory
Weakness Enumeration
CWE-ID
CWE Name
Source
CWE-400
Uncontrolled Resource Consumption
NIST  
Change History
19 change records found show changes
CVE Modified by Red Hat, Inc.
6/16/2026 7:08:17 PM
Action
Type
Old Value
New Value
Added
Affected
[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]
CVE Status Change
4/22/2026 8:35:47 PM
Action
Type
Old Value
New Value
CVE Modified by CVE
11/20/2024 8:03:37 PM
Action
Type
Old Value
New Value
Added
Reference
http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html
Added
Reference
http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00006.html
Added
Reference
http://marc.info/?l=bugtraq&m=129190899612998&w=2
Added
Reference
http://marc.info/?l=bugtraq&m=129190899612998&w=2
Added
Reference
http://osvdb.org/55553
Added
Reference
http://secunia.com/advisories/35691
Added
Reference
http://secunia.com/advisories/35721
Added
Reference
http://secunia.com/advisories/35793
Added
Reference
http://secunia.com/advisories/35865
Added
Reference
http://secunia.com/advisories/37152
Added
Reference
http://secunia.com/advisories/37221
Added
Reference
http://security.gentoo.org/glsa/glsa-200907-04.xml
Added
Reference
http://support.apple.com/kb/HT3937
Added
Reference
http://svn.apache.org/viewvc/httpd/httpd/trunk/CHANGES?r1=790587&r2=790586&pathrev=790587
Added
Reference
http://svn.apache.org/viewvc/httpd/httpd/trunk/CHANGES?revision=790587
Added
Reference
http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/proxy/mod_proxy_http.c?r1=790587&r2=790586&pathrev=790587
Added
Reference
http://svn.apache.org/viewvc?view=rev&revision=790587
Added
Reference
http://wiki.rpath.com/Advisories:rPSA-2009-0142
Added
Reference
http://www-01.ibm.com/support/docview.wss?uid=swg1PK91259
Added
Reference
http://www-01.ibm.com/support/docview.wss?uid=swg1PK99480
Added
Reference
http://www.debian.org/security/2009/dsa-1834
Added
Reference
http://www.mandriva.com/security/advisories?name=MDVSA-2009:149
Added
Reference
http://www.mandriva.com/security/advisories?name=MDVSA-2013:150
Added
Reference
http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html
Added
Reference
http://www.redhat.com/support/errata/RHSA-2009-1156.html
Added
Reference
http://www.securityfocus.com/archive/1/507852/100/0/threaded
Added
Reference
http://www.securityfocus.com/archive/1/507857/100/0/threaded
Added
Reference
http://www.securityfocus.com/bid/35565
Added
Reference
http://www.securitytracker.com/id?1022509
Added
Reference
http://www.ubuntu.com/usn/USN-802-1
Added
Reference
http://www.vupen.com/english/advisories/2009/3184
Added
Reference
https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E
Added
Reference
https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E
Added
Reference
https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E
Added
Reference
https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E
Added
Reference
https://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3E
Added
Reference
https://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3E
Added
Reference
https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E
Added
Reference
https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E
Added
Reference
https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E
Added
Reference
https://lists.apache.org/thread.html/rb33be0aa9bd8cac9536293e3821dcd4cf8180ad95a8036eedd46365e%40%3Cusers.mina.apache.org%3E
Added
Reference
https://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8%40%3Ccvs.httpd.apache.org%3E
Added
Reference
https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E
Added
Reference
https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E
Added
Reference
https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E
Added
Reference
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12330
Added
Reference
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8616
Added
Reference
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9403
Added
Reference
https://rhn.redhat.com/errata/RHSA-2009-1148.html
Added
Reference
https://www.redhat.com/archives/fedora-package-announce/2009-August/msg01363.html
CVE Modified by Red Hat, Inc.
5/13/2024 10:07:11 PM
Action
Type
Old Value
New Value
CVE Modified by Red Hat, Inc.
2/12/2023 9:20:13 PM
Action
Type
Old Value
New Value
Changed
Description
CVE-2009-1890 httpd: mod_proxy reverse proxy DoS (infinite loop)
The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which allows remote attackers to cause a denial of service (CPU consumption) via crafted requests.
Removed
CVSS V2
Red Hat, Inc. (AV:N/AC:L/Au:N/C:N/I:N/A:P)
Removed
Reference
https://access.redhat.com/errata/RHSA-2009:1148 [No Types Assigned]
Removed
Reference
https://access.redhat.com/errata/RHSA-2009:1155 [No Types Assigned]
Removed
Reference
https://access.redhat.com/errata/RHSA-2009:1156 [No Types Assigned]
Removed
Reference
https://access.redhat.com/errata/RHSA-2009:1160 [No Types Assigned]
Removed
Reference
https://access.redhat.com/security/cve/CVE-2009-1890 [No Types Assigned]
Removed
Reference
https://bugzilla.redhat.com/show_bug.cgi?id=509375 [No Types Assigned]
CVE Modified by Red Hat, Inc.
2/02/2023 12:16:28 PM
Action
Type
Old Value
New Value
Changed
Description
The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which allows remote attackers to cause a denial of service (CPU consumption) via crafted requests.
CVE-2009-1890 httpd: mod_proxy reverse proxy DoS (infinite loop)
Added
CVSS V2
Red Hat, Inc. (AV:N/AC:L/Au:N/C:N/I:N/A:P)
Added
Reference
https://access.redhat.com/errata/RHSA-2009:1148 [No Types Assigned]
Added
Reference
https://access.redhat.com/errata/RHSA-2009:1155 [No Types Assigned]
Added
Reference
https://access.redhat.com/errata/RHSA-2009:1156 [No Types Assigned]
Added
Reference
https://access.redhat.com/errata/RHSA-2009:1160 [No Types Assigned]
Added
Reference
https://access.redhat.com/security/cve/CVE-2009-1890 [No Types Assigned]
Added
Reference
https://bugzilla.redhat.com/show_bug.cgi?id=509375 [No Types Assigned]
Added
Reference
https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E [No Types Assigned]
Added
Reference
https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E [No Types Assigned]
Added
Reference
https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E [No Types Assigned]
Added
Reference
https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E [No Types Assigned]
Added
Reference
https://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3E [No Types Assigned]
Added
Reference
https://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3E [No Types Assigned]
Added
Reference
https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E [No Types Assigned]
Added
Reference
https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E [No Types Assigned]
Added
Reference
https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E [No Types Assigned]
Added
Reference
https://lists.apache.org/thread.html/rb33be0aa9bd8cac9536293e3821dcd4cf8180ad95a8036eedd46365e%40%3Cusers.mina.apache.org%3E [No Types Assigned]
Added
Reference
https://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8%40%3Ccvs.httpd.apache.org%3E [No Types Assigned]
Added
Reference
https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E [No Types Assigned]
Added
Reference
https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E [No Types Assigned]
Added
Reference
https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E [No Types Assigned]
Removed
Reference
https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f@%3Ccvs.httpd.apache.org%3E [Mailing List, Vendor Advisory]
Removed
Reference
https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53@%3Ccvs.httpd.apache.org%3E [Mailing List, Vendor Advisory]
Removed
Reference
https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7@%3Ccvs.httpd.apache.org%3E [Mailing List, Vendor Advisory]
Removed
Reference
https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f@%3Ccvs.httpd.apache.org%3E [Mailing List, Vendor Advisory]
Removed
Reference
https://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919@%3Ccvs.httpd.apache.org%3E [Mailing List, Vendor Advisory]
Removed
Reference
https://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be@%3Ccvs.httpd.apache.org%3E [Mailing List, Vendor Advisory]
Removed
Reference
https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b@%3Ccvs.httpd.apache.org%3E [Mailing List, Vendor Advisory]
Removed
Reference
https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920@%3Ccvs.httpd.apache.org%3E [Mailing List, Vendor Advisory]
Removed
Reference
https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24@%3Ccvs.httpd.apache.org%3E [Mailing List, Vendor Advisory]
Removed
Reference
https://lists.apache.org/thread.html/rb33be0aa9bd8cac9536293e3821dcd4cf8180ad95a8036eedd46365e@%3Cusers.mina.apache.org%3E [Mailing List, Vendor Advisory]
Removed
Reference
https://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8@%3Ccvs.httpd.apache.org%3E [Mailing List, Vendor Advisory]
Removed
Reference
https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064@%3Ccvs.httpd.apache.org%3E [Mailing List, Vendor Advisory]
Removed
Reference
https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9@%3Ccvs.httpd.apache.org%3E [Mailing List, Vendor Advisory]
Removed
Reference
https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b@%3Ccvs.httpd.apache.org%3E [Mailing List, Vendor Advisory]
Modified Analysis by NIST
9/19/2022 3:56:22 PM
Action
Type
Old Value
New Value
Added
CWE
NIST CWE-400
Removed
CWE
NIST CWE-189
Changed
CPE Configuration
Record truncated, showing 2048 of 8202 characters.
View Entire Change Record
OR
*cpe:2.3:a:apache:http_server:*:*:win32:*:*:*:*:*
*cpe:2.3:a:apache:http_server:-:*:*:*:*:*:*:*
*cpe:2.3:a:apache:http_server:0.8.11:*:*:*:*:*:*:*
*cpe:2.3:a:apache:http_server:0.8.14:*:*:*:*:*:*:*
*cpe:2.3:a:apache:http_server:1.0:*:*:*:*:*:*:*
*cpe:2.3:a:apache:http_server:1.0.2:*:*:*:*:*:*:*
*cpe:2.3:a:apache:http_server:1.0.3:*:*:*:*:*:*:*
*cpe:2.3:a:apache:http_server:1.0.5:*:*:*:*:*:*:*
*cpe:2.3:a:apache:http_server:1.1:*:*:*:*:*:*:*
*cpe:2.3:a:apache:http_server:1.1.1:*:*:*:*:*:*:*
*cpe:2.3:a:apache:http_server:1.2:*:*:*:*:*:*:*
*cpe:2.3:a:apache:http_server:1.2.4:*:*:*:*:*:*:*
*cpe:2.3:a:apache:http_server:1.2.5:*:*:*:*:*:*:*
*cpe:2.3:a:apache:http_server:1.2.6:*:*:*:*:*:*:*
*cpe:2.3:a:apache:http_server:1.2.9:*:*:*:*:*:*:*
*cpe:2.3:a:apache:http_server:1.3:*:*:*:*:*:*:*
*cpe:2.3:a:apache:http_server:1.3.0:*:*:*:*:*:*:*
*cpe:2.3:a:apache:http_server:1.3.1:*:*:*:*:*:*:*
*cpe:2.3:a:apache:http_server:1.3.1.1:*:*:*:*:*:*:*
*cpe:2.3:a:apache:http_server:1.3.2:*:*:*:*:*:*:*
*cpe:2.3:a:apache:http_server:1.3.3:*:*:*:*:*:*:*
*cpe:2.3:a:apache:http_server:1.3.4:*:*:*:*:*:*:*
*cpe:2.3:a:apache:http_server:1.3.5:*:*:*:*:*:*:*
*cpe:2.3:a:apache:http_server:1.3.6:*:*:*:*:*:*:*
*cpe:2.3:a:apache:http_server:1.3.6:*:win32:*:*:*:*:*
*cpe:2.3:a:apache:http_server:1.3.7:*:*:*:*:*:*:*
*cpe:2.3:a:apache:http_server:1.3.7:*:dev:*:*:*:*:*
*cpe:2.3:a:apache:http_server:1.3.8:*:*:*:*:*:*:*
*cpe:2.3:a:apache:http_server:1.3.9:*:*:*:*:*:*:*
*cpe:2.3:a:apache:http_server:1.3.9:*:win32:*:*:*:*:*
*cpe:2.3:a:apache:http_server:1.3.10:*:*:*:*:*:*:*
*cpe:2.3:a:apache:http_server:1.3.11:*:*:*:*:*:*:*
*cpe:2.3:a:apache:http_server:1.3.11:*:win32:*:*:*:*:*
*cpe:2.3:a:apache:http_server:1.3.12:*:*:*:*:*:*:*
*cpe:2.3:a:apache:http_server:1.3.12:*:win32:*:*:*:*:*
*cpe:2.3:a:apache:http_server:1.3.13:*:*:*:*:*:*:*
*cpe:2.3:a:apache:http_server:1.3.13:*:win32
OR
*cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* versions from (including) 2.2.0 up to (excluding) 2.2.12
Added
CPE Configuration
OR
*cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:*
*cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:-:*:*:*
*cpe:2.3:o:canonical:ubuntu_linux:8.10:*:*:*:*:*:*:*
*cpe:2.3:o:canonical:ubuntu_linux:9.04:*:*:*:*:*:*:*
Added
CPE Configuration
OR
*cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*
*cpe:2.3:o:debian:debian_linux:5.0:*:*:*:*:*:*:*
*cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:*
Added
CPE Configuration
OR
*cpe:2.3:o:fedoraproject:fedora:11:*:*:*:*:*:*:*
Added
CPE Configuration
OR
*cpe:2.3:o:redhat:enterprise_linux_desktop:5.0:*:*:*:*:*:*:*
*cpe:2.3:o:redhat:enterprise_linux_eus:5.3:*:*:*:*:*:*:*
*cpe:2.3:o:redhat:enterprise_linux_server:5.0:*:*:*:*:*:*:*
*cpe:2.3:o:redhat:enterprise_linux_server_aus:5.3:*:*:*:*:*:*:*
*cpe:2.3:o:redhat:enterprise_linux_workstation:5.0:*:*:*:*:*:*:*
Changed
Reference Type
http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html No Types Assigned
http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html Broken Link, Mailing List
Changed
Reference Type
http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00006.html No Types Assigned
http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00006.html Mailing List, Third Party Advisory
Changed
Reference Type
http://marc.info/?l=bugtraq&m=129190899612998&w=2 No Types Assigned
http://marc.info/?l=bugtraq&m=129190899612998&w=2 Issue Tracking, Mailing List, Third Party Advisory
Changed
Reference Type
http://osvdb.org/55553 No Types Assigned
http://osvdb.org/55553 Broken Link
Changed
Reference Type
http://secunia.com/advisories/35691 Vendor Advisory
http://secunia.com/advisories/35691 Not Applicable, Vendor Advisory
Changed
Reference Type
http://secunia.com/advisories/35721 No Types Assigned
http://secunia.com/advisories/35721 Not Applicable
Changed
Reference Type
http://secunia.com/advisories/35793 No Types Assigned
http://secunia.com/advisories/35793 Not Applicable
Changed
Reference Type
http://secunia.com/advisories/35865 No Types Assigned
http://secunia.com/advisories/35865 Not Applicable
Changed
Reference Type
http://secunia.com/advisories/37152 Vendor Advisory
http://secunia.com/advisories/37152 Not Applicable, Vendor Advisory
Changed
Reference Type
http://secunia.com/advisories/37221 Vendor Advisory
http://secunia.com/advisories/37221 Not Applicable, Vendor Advisory
Changed
Reference Type
http://security.gentoo.org/glsa/glsa-200907-04.xml No Types Assigned
http://security.gentoo.org/glsa/glsa-200907-04.xml Third Party Advisory
Changed
Reference Type
http://support.apple.com/kb/HT3937 No Types Assigned
http://support.apple.com/kb/HT3937 Broken Link
Changed
Reference Type
http://svn.apache.org/viewvc/httpd/httpd/trunk/CHANGES?r1=790587&r2=790586&pathrev=790587 Vendor Advisory
http://svn.apache.org/viewvc/httpd/httpd/trunk/CHANGES?r1=790587&r2=790586&pathrev=790587 Patch, Vendor Advisory
Changed
Reference Type
http://wiki.rpath.com/Advisories:rPSA-2009-0142 No Types Assigned
http://wiki.rpath.com/Advisories:rPSA-2009-0142 Broken Link
Changed
Reference Type
http://www-01.ibm.com/support/docview.wss?uid=swg1PK91259 No Types Assigned
http://www-01.ibm.com/support/docview.wss?uid=swg1PK91259 Third Party Advisory
Changed
Reference Type
http://www-01.ibm.com/support/docview.wss?uid=swg1PK99480 No Types Assigned
http://www-01.ibm.com/support/docview.wss?uid=swg1PK99480 Third Party Advisory
Changed
Reference Type
http://www.debian.org/security/2009/dsa-1834 No Types Assigned
http://www.debian.org/security/2009/dsa-1834 Third Party Advisory
Changed
Reference Type
http://www.mandriva.com/security/advisories?name=MDVSA-2009:149 No Types Assigned
http://www.mandriva.com/security/advisories?name=MDVSA-2009:149 Broken Link
Changed
Reference Type
http://www.mandriva.com/security/advisories?name=MDVSA-2013:150 No Types Assigned
http://www.mandriva.com/security/advisories?name=MDVSA-2013:150 Broken Link
Changed
Reference Type
http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html No Types Assigned
http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html Third Party Advisory
Changed
Reference Type
http://www.redhat.com/support/errata/RHSA-2009-1156.html No Types Assigned
http://www.redhat.com/support/errata/RHSA-2009-1156.html Third Party Advisory
Changed
Reference Type
http://www.securityfocus.com/archive/1/507852/100/0/threaded No Types Assigned
http://www.securityfocus.com/archive/1/507852/100/0/threaded Third Party Advisory, VDB Entry
Changed
Reference Type
http://www.securityfocus.com/archive/1/507857/100/0/threaded No Types Assigned
http://www.securityfocus.com/archive/1/507857/100/0/threaded Third Party Advisory, VDB Entry
Changed
Reference Type
http://www.securityfocus.com/bid/35565 No Types Assigned
http://www.securityfocus.com/bid/35565 Third Party Advisory, VDB Entry
Changed
Reference Type
http://www.securitytracker.com/id?1022509 No Types Assigned
http://www.securitytracker.com/id?1022509 Broken Link, Third Party Advisory, VDB Entry
Changed
Reference Type
http://www.ubuntu.com/usn/USN-802-1 No Types Assigned
http://www.ubuntu.com/usn/USN-802-1 Third Party Advisory
Changed
Reference Type
http://www.vupen.com/english/advisories/2009/3184 Vendor Advisory
http://www.vupen.com/english/advisories/2009/3184 Permissions Required, Vendor Advisory
Changed
Reference Type
https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f@%3Ccvs.httpd.apache.org%3E No Types Assigned
https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f@%3Ccvs.httpd.apache.org%3E Mailing List, Vendor Advisory
Changed
Reference Type
https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53@%3Ccvs.httpd.apache.org%3E No Types Assigned
https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53@%3Ccvs.httpd.apache.org%3E Mailing List, Vendor Advisory
Changed
Reference Type
https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7@%3Ccvs.httpd.apache.org%3E No Types Assigned
https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7@%3Ccvs.httpd.apache.org%3E Mailing List, Vendor Advisory
Changed
Reference Type
https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f@%3Ccvs.httpd.apache.org%3E No Types Assigned
https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f@%3Ccvs.httpd.apache.org%3E Mailing List, Vendor Advisory
Changed
Reference Type
https://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919@%3Ccvs.httpd.apache.org%3E No Types Assigned
https://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919@%3Ccvs.httpd.apache.org%3E Mailing List, Vendor Advisory
Changed
Reference Type
https://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be@%3Ccvs.httpd.apache.org%3E No Types Assigned
https://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be@%3Ccvs.httpd.apache.org%3E Mailing List, Vendor Advisory
Changed
Reference Type
https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b@%3Ccvs.httpd.apache.org%3E No Types Assigned
https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b@%3Ccvs.httpd.apache.org%3E Mailing List, Vendor Advisory
Changed
Reference Type
https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920@%3Ccvs.httpd.apache.org%3E No Types Assigned
https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920@%3Ccvs.httpd.apache.org%3E Mailing List, Vendor Advisory
Changed
Reference Type
https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24@%3Ccvs.httpd.apache.org%3E No Types Assigned
https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24@%3Ccvs.httpd.apache.org%3E Mailing List, Vendor Advisory
Changed
Reference Type
https://lists.apache.org/thread.html/rb33be0aa9bd8cac9536293e3821dcd4cf8180ad95a8036eedd46365e@%3Cusers.mina.apache.org%3E No Types Assigned
https://lists.apache.org/thread.html/rb33be0aa9bd8cac9536293e3821dcd4cf8180ad95a8036eedd46365e@%3Cusers.mina.apache.org%3E Mailing List, Vendor Advisory
Changed
Reference Type
https://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8@%3Ccvs.httpd.apache.org%3E No Types Assigned
https://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8@%3Ccvs.httpd.apache.org%3E Mailing List, Vendor Advisory
Changed
Reference Type
https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064@%3Ccvs.httpd.apache.org%3E No Types Assigned
https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064@%3Ccvs.httpd.apache.org%3E Mailing List, Vendor Advisory
Changed
Reference Type
https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9@%3Ccvs.httpd.apache.org%3E No Types Assigned
https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9@%3Ccvs.httpd.apache.org%3E Mailing List, Vendor Advisory
Changed
Reference Type
https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b@%3Ccvs.httpd.apache.org%3E No Types Assigned
https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b@%3Ccvs.httpd.apache.org%3E Mailing List, Vendor Advisory
Changed
Reference Type
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12330 No Types Assigned
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12330 Third Party Advisory
Changed
Reference Type
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8616 No Types Assigned
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8616 Third Party Advisory
Changed
Reference Type
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9403 No Types Assigned
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9403 Third Party Advisory
Changed
Reference Type
https://rhn.redhat.com/errata/RHSA-2009-1148.html No Types Assigned
https://rhn.redhat.com/errata/RHSA-2009-1148.html Third Party Advisory
Changed
Reference Type
https://www.redhat.com/archives/fedora-package-announce/2009-August/msg01363.html No Types Assigned
https://www.redhat.com/archives/fedora-package-announce/2009-August/msg01363.html Third Party Advisory
CVE Modified by Red Hat, Inc.
7/14/2021 3:15:08 AM
Action
Type
Old Value
New Value
Added
Reference
https://lists.apache.org/thread.html/rb33be0aa9bd8cac9536293e3821dcd4cf8180ad95a8036eedd46365e@%3Cusers.mina.apache.org%3E [No Types Assigned]
CVE Modified by Red Hat, Inc.
6/06/2021 7:15:15 AM
Action
Type
Old Value
New Value
Added
Reference
https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f@%3Ccvs.httpd.apache.org%3E [No Types Assigned]
CVE Modified by Red Hat, Inc.
6/03/2021 4:15:12 AM
Action
Type
Old Value
New Value
Added
Reference
https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24@%3Ccvs.httpd.apache.org%3E [No Types Assigned]
Added
Reference
https://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8@%3Ccvs.httpd.apache.org%3E [No Types Assigned]
CVE Modified by Red Hat, Inc.
3/30/2021 9:15:18 AM
Action
Type
Old Value
New Value
Added
Reference
https://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be@%3Ccvs.httpd.apache.org%3E [No Types Assigned]
Added
Reference
https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920@%3Ccvs.httpd.apache.org%3E [No Types Assigned]
Added
Reference
https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064@%3Ccvs.httpd.apache.org%3E [No Types Assigned]
CVE Modified by Red Hat, Inc.
3/30/2021 8:15:45 AM
Action
Type
Old Value
New Value
Added
Reference
https://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919@%3Ccvs.httpd.apache.org%3E [No Types Assigned]
Added
Reference
https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b@%3Ccvs.httpd.apache.org%3E [No Types Assigned]
Added
Reference
https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9@%3Ccvs.httpd.apache.org%3E [No Types Assigned]
CVE Modified by Red Hat, Inc.
4/01/2020 12:15:20 PM
Action
Type
Old Value
New Value
Added
Reference
https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b@%3Ccvs.httpd.apache.org%3E [No Types Assigned]
CVE Modified by Red Hat, Inc.
4/01/2020 11:15:26 AM
Action
Type
Old Value
New Value
Added
Reference
https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7@%3Ccvs.httpd.apache.org%3E [No Types Assigned]
CVE Modified by Red Hat, Inc.
8/15/2019 5:15:21 AM
Action
Type
Old Value
New Value
Added
Reference
https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f@%3Ccvs.httpd.apache.org%3E [No Types Assigned]
Added
Reference
https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53@%3Ccvs.httpd.apache.org%3E [No Types Assigned]
CPE Deprecation Remap by NIST
10/30/2018 12:25:27 PM
Action
Type
Old Value
New Value
Changed
CPE Configuration
OR
*cpe:2.3:a:apache:http_server:2.2.5:*:*:*:*:*:*:*
OR
*cpe:2.3:a:apache:http_server:-:*:*:*:*:*:*:*
CVE Modified by Red Hat, Inc.
10/10/2018 3:38:39 PM
Action
Type
Old Value
New Value
Added
Reference
http://www.securityfocus.com/archive/1/507852/100/0/threaded [No Types Assigned]
Added
Reference
http://www.securityfocus.com/archive/1/507857/100/0/threaded [No Types Assigned]
Removed
Reference
http://www.securityfocus.com/archive/1/archive/1/507852/100/0/threaded [No Types Assigned]
Removed
Reference
http://www.securityfocus.com/archive/1/archive/1/507857/100/0/threaded [No Types Assigned]
CVE Modified by Red Hat, Inc.
9/28/2017 9:34:38 PM
Action
Type
Old Value
New Value
Added
Reference
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12330 [No Types Assigned]
Added
Reference
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8616 [No Types Assigned]
Added
Reference
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9403 [No Types Assigned]
Removed
Reference
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12330 [No Types Assigned]
Removed
Reference
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8616 [No Types Assigned]
Removed
Reference
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9403 [No Types Assigned]
Initial CVE Analysis
7/06/2009 8:11:00 AM
Action
Type
Old Value
New Value
Quick Info
CVE Dictionary Entry: CVE-2009-1890 NVD
Published Date: 07/05/2009 NVD
Last Modified: 06/16/2026
Source: Red Hat, Inc.