CVE-2010-0010
Summary
| CVE | CVE-2010-0010 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-02-02 16:30:02 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Integer overflow in the ap_proxy_send_fb function in proxy/proxy_util.c in mod_proxy in the Apache HTTP Server before 1.3.42 on 64-bit platforms allows remote origin servers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a large chunk size that triggers a heap-based buffer overflow. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Http Server | 0.8.11 | All | All | All |
| Application | Apache | Http Server | 0.8.14 | All | All | All |
| Application | Apache | Http Server | 1.0 | All | All | All |
| Application | Apache | Http Server | 1.0.3 | All | All | All |
| Application | Apache | Http Server | 1.0.5 | All | All | All |
| Application | Apache | Http Server | 1.1 | All | All | All |
| Application | Apache | Http Server | 1.2 | All | All | All |
| Application | Apache | Http Server | 1.2.4 | All | All | All |
| Application | Apache | Http Server | 1.2.5 | All | All | All |
| Application | Apache | Http Server | 1.2.6 | All | All | All |
| Application | Apache | Http Server | 1.3 | All | All | All |
| Application | Apache | Http Server | 1.3.0 | All | All | All |
| Application | Apache | Http Server | 1.3.1 | All | All | All |
| Application | Apache | Http Server | 1.3.10 | All | All | All |
| Application | Apache | Http Server | 1.3.11 | All | All | All |
| Application | Apache | Http Server | 1.3.12 | All | All | All |
| Application | Apache | Http Server | 1.3.13 | All | All | All |
| Application | Apache | Http Server | 1.3.14 | All | All | All |
| Application | Apache | Http Server | 1.3.15 | All | All | All |
| Application | Apache | Http Server | 1.3.17 | All | All | All |
| Application | Apache | Http Server | 1.3.18 | All | All | All |
| Application | Apache | Http Server | 1.3.19 | All | All | All |
| Application | Apache | Http Server | 1.3.2 | All | All | All |
| Application | Apache | Http Server | 1.3.20 | All | All | All |
| Application | Apache | Http Server | 1.3.22 | All | All | All |
| Application | Apache | Http Server | 1.3.23 | All | All | All |
| Application | Apache | Http Server | 1.3.24 | All | All | All |
| Application | Apache | Http Server | 1.3.25 | All | All | All |
| Application | Apache | Http Server | 1.3.26 | All | All | All |
| Application | Apache | Http Server | 1.3.27 | All | All | All |
| Application | Apache | Http Server | 1.3.28 | All | All | All |
| Application | Apache | Http Server | 1.3.29 | All | All | All |
| Application | Apache | Http Server | 1.3.3 | All | All | All |
| Application | Apache | Http Server | 1.3.30 | All | All | All |
| Application | Apache | Http Server | 1.3.31 | All | All | All |
| Application | Apache | Http Server | 1.3.32 | All | All | All |
| Application | Apache | Http Server | 1.3.33 | All | All | All |
| Application | Apache | Http Server | 1.3.34 | All | All | All |
| Application | Apache | Http Server | 1.3.35 | All | All | All |
| Application | Apache | Http Server | 1.3.36 | All | All | All |
| Application | Apache | Http Server | 1.3.37 | All | All | All |
| Application | Apache | Http Server | 1.3.38 | All | All | All |
| Application | Apache | Http Server | 1.3.39 | All | All | All |
| Application | Apache | Http Server | 1.3.4 | All | All | All |
| Application | Apache | Http Server | 1.3.40 | All | All | All |
| Application | Apache | Http Server | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [security-announce] SUSE Security Summary Report: SUSE-SR:2010:010 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Apache mod_proxy Integer Overflow May Let Remote Users Execute Arbitrary Code - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| '[security bulletin] HPSBOV02683 SSRT090208 rev.1 - HP Secure Web Server (SWS) for OpenVMS running Ap' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| SUSE update for Multiple Packages - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| CVE-2010-0010: Apache mod_proxy vulnerability : pi3 blog | af854a3a-2127-422b-91ae-364da2661108 | blog.pi3.com.pl | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| Apache 1.3 mod_proxy HTTP Chunked Encoding Integer Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| Files ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.org | Exploit |
| site.pi3.com.pl/adv/mod_proxy.txt | af854a3a-2127-422b-91ae-364da2661108 | site.pi3.com.pl | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| NEOHAPSIS - Peace of Mind Through Integrity and Insight | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | Exploit |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| 404 Not Found | af854a3a-2127-422b-91ae-364da2661108 | httpd.apache.org | |
| Apache mod_proxy "ap_proxy_send_fb()" Integer Truncation Vulnerability - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2010-02-03 | Joshua Bressers | This issue does not affect the Apache HTTP Server versions 2 and greater. This flaw does not affect any supported versions of Red Hat Enterprise Linux. This flaw does affect Red Hat Network Proxy and Red Hat Network Satellite. While those products do not use this feature, we are tracking the issue with the following bug: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-0010 |
There are currently no legacy QID mappings associated with this CVE.