Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 528756 - (CVE-2009-2699) CVE-2009-2699 httpd (apr): Improper pollset feature error handling on Solaris - DoS (hang)
CVE-2009-2699 httpd (apr): Improper pollset feature error handling on Solaris...
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
https://issues.apache.org/bugzilla/sh...
impact=moderate,public=20091005,repor...
: Security
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2009-10-13 11:42 EDT by Jan Lieskovsky
Modified: 2009-11-13 09:53 EST (History)
2 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2009-11-13 09:25:35 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Jan Lieskovsky 2009-10-13 11:42:29 EDT
Common Vulnerabilities and Exposures assigned an identifier CVE-2009-2699 to
the following vulnerability:

The Solaris pollset feature in the Event Port backend in
poll/unix/port.c in the Apache Portable Runtime (APR) library before
1.3.9, as used in the Apache HTTP Server before 2.2.14 and other
products, does not properly handle errors, which allows remote
attackers to cause a denial of service (daemon hang) via unspecified
HTTP requests, related to the prefork and event MPMs.

References:
-----------
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2699
http://www.apache.org/dist/httpd/CHANGES_2.2.14
https://issues.apache.org/bugzilla/show_bug.cgi?id=47645
http://www.securityfocus.com/bid/36596
http://securitytracker.com/id?1022988
http://xforce.iss.net/xforce/xfdb/53666

Note: This is Solaris / OpenSolaris OS specific issue and does NOT affect
      the versions of the httpd package, as shipped
      in Red Hat Enterprise Linux OS.
Comment 1 Tomas Hoger 2009-11-10 09:29:00 EST
Upstream commit:
  http://svn.apache.org/viewvc?view=revision&revision=807263
Comment 2 Tomas Hoger 2009-11-13 09:25:35 EST
This issue affected httpd 2.2.x running on Solaris.  Affected httpd version shipped in JBoss Enterprise Web Server for Solaris was fixed via:

https://support.redhat.com/jbossnetwork/restricted/softwareDetail.html?softwareId=1013

Note You need to log in before you can comment on or make changes to this bug.