Quoting httpd 2.2 security page: http://httpd.apache.org/security/vulnerabilities_22.html#2.2.15 moderate: mod_proxy_ajp DoS CVE-2010-0408 mod_proxy_ajp would return the wrong status code if it encountered an error causing a backend server to be put into an error state until the retry timeout expired. A remote attacker could send malicious requests to trigger this issue, resulting in a denial of service. Affects: 2.2.0 - 2.2.14 Upstream commit: http://svn.apache.org/viewvc?view=revision&revision=917876
Please elevate this report to a status of URGENT for a solution.
This issue was rated as having moderate security impact [1]. Security impact determines priority of the bug report. If you believe our impact rating is incorrect, please explain the reasons. The issue is being fixed in the upcoming updates already being worked on. [1] http://www.redhat.com/security/updates/classification/
This issue has been addressed in following products: Red Hat Enterprise Linux 5 Via RHSA-2010:0168 https://rhn.redhat.com/errata/RHSA-2010-0168.html
httpd-2.2.15-1.fc12 has been submitted as an update for Fedora 12. http://admin.fedoraproject.org/updates/httpd-2.2.15-1.fc12
httpd-2.2.15-1.fc13 has been submitted as an update for Fedora 13. http://admin.fedoraproject.org/updates/httpd-2.2.15-1.fc13
httpd-2.2.15-1.fc11 has been submitted as an update for Fedora 11. http://admin.fedoraproject.org/updates/httpd-2.2.15-1.fc11
httpd-2.2.15-1.fc12.1 has been submitted as an update for Fedora 12. http://admin.fedoraproject.org/updates/httpd-2.2.15-1.fc12.1
httpd-2.2.15-1.fc11.1 has been submitted as an update for Fedora 11. http://admin.fedoraproject.org/updates/httpd-2.2.15-1.fc11.1
httpd-2.2.15-1.fc13 has been pushed to the Fedora 13 stable repository. If problems still persist, please make note of it in this bug report.
httpd-2.2.15-1.fc11.1 has been pushed to the Fedora 11 stable repository. If problems still persist, please make note of it in this bug report.
This issue has been addressed in following products: JBEWS 1.0 for RHEL 4 JBEWS 1.0 for RHEL 5 Via RHSA-2010:0396 https://rhn.redhat.com/errata/RHSA-2010-0396.html
httpd-2.2.15-1.fc12.2 has been pushed to the Fedora 12 stable repository. If problems still persist, please make note of it in this bug report.