CVE-2004-0492 - CVE House
Back to Database
Status published Critical CVE-2004-0492

Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25...

Vulnerability Description

Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes a large amount of data to be copied.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2004-0492

Credits & Attribution

No credits recorded in the NVD database.

References

Affected Vendor

Affected Software

http server, virtualvault, webproxy, propack, vvos, openbsd
Vulnerable Versions:
1.3.26, 1.3.27, 1.3.28, 1.3.29, 1.3.31, 11.0.4, 2.0, 2.1, 1.3.26.1, 1.3.26.2, 2.4, 11.04, 3.4, 3.5

Timeline

Official Publish: June 23rd, 2004
Last Modified: August 8th, 2024
Added to House: July 18th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.