CVE-2012-4557

Publication date 30 November 2012

Last updated 24 July 2024


Ubuntu priority

The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2.21 places a worker node into an error state upon detection of a long request-processing time, which allows remote attackers to cause a denial of service (worker consumption) via an expensive request.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
apache2 12.10 quantal
Not affected
12.04 LTS precise
Not affected
11.10 oneiric
Fixed 2.2.20-1ubuntu1.4
10.04 LTS lucid
Fixed 2.2.14-5ubuntu8.11
8.04 LTS hardy
Fixed 2.2.8-1ubuntu0.25

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
apache2

References

Related Ubuntu Security Notices (USN)

    • USN-1765-1
    • Apache HTTP Server vulnerabilities
    • 18 March 2013

Other references