Bug 528756 (CVE-2009-2699)

Summary: CVE-2009-2699 httpd (apr): Improper pollset feature error handling on Solaris - DoS (hang)
Product: [Other] Security Response Reporter: Jan Lieskovsky <jlieskov>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: pcheung, rmeggins
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
URL: https://issues.apache.org/bugzilla/show_bug.cgi?id=47645
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2009-11-13 14:25:35 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Jan Lieskovsky 2009-10-13 15:42:29 UTC
Common Vulnerabilities and Exposures assigned an identifier CVE-2009-2699 to
the following vulnerability:

The Solaris pollset feature in the Event Port backend in
poll/unix/port.c in the Apache Portable Runtime (APR) library before
1.3.9, as used in the Apache HTTP Server before 2.2.14 and other
products, does not properly handle errors, which allows remote
attackers to cause a denial of service (daemon hang) via unspecified
HTTP requests, related to the prefork and event MPMs.

References:
-----------
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2699
http://www.apache.org/dist/httpd/CHANGES_2.2.14
https://issues.apache.org/bugzilla/show_bug.cgi?id=47645
http://www.securityfocus.com/bid/36596
http://securitytracker.com/id?1022988
http://xforce.iss.net/xforce/xfdb/53666

Note: This is Solaris / OpenSolaris OS specific issue and does NOT affect
      the versions of the httpd package, as shipped
      in Red Hat Enterprise Linux OS.

Comment 1 Tomas Hoger 2009-11-10 14:29:00 UTC
Upstream commit:
  http://svn.apache.org/viewvc?view=revision&revision=807263

Comment 2 Tomas Hoger 2009-11-13 14:25:35 UTC
This issue affected httpd 2.2.x running on Solaris.  Affected httpd version shipped in JBoss Enterprise Web Server for Solaris was fixed via:

https://support.redhat.com/jbossnetwork/restricted/softwareDetail.html?softwareId=1013