Common Vulnerabilities and Exposures assigned an identifier CVE-2009-2699 to the following vulnerability: The Solaris pollset feature in the Event Port backend in poll/unix/port.c in the Apache Portable Runtime (APR) library before 1.3.9, as used in the Apache HTTP Server before 2.2.14 and other products, does not properly handle errors, which allows remote attackers to cause a denial of service (daemon hang) via unspecified HTTP requests, related to the prefork and event MPMs. References: ----------- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2699 http://www.apache.org/dist/httpd/CHANGES_2.2.14 https://issues.apache.org/bugzilla/show_bug.cgi?id=47645 http://www.securityfocus.com/bid/36596 http://securitytracker.com/id?1022988 http://xforce.iss.net/xforce/xfdb/53666 Note: This is Solaris / OpenSolaris OS specific issue and does NOT affect the versions of the httpd package, as shipped in Red Hat Enterprise Linux OS.
Upstream commit: http://svn.apache.org/viewvc?view=revision&revision=807263
This issue affected httpd 2.2.x running on Solaris. Affected httpd version shipped in JBoss Enterprise Web Server for Solaris was fixed via: https://support.redhat.com/jbossnetwork/restricted/softwareDetail.html?softwareId=1013