Total vulnerabilities in the database
The authentication module for Apache 2.0.40 through 2.0.45 on Unix does not properly handle threads safely when using the crypt_r or crypt functions, which allows remote attackers to cause a denial of service (failed Basic authentication with valid usernames and passwords) when a threaded MPM is used.
Software | From | Fixed in |
---|---|---|
apache / http_server | 2.0.42 | 2.0.42.x |
apache / http_server | 2.0.44 | 2.0.44.x |
apache / http_server | 2.0.41 | 2.0.41.x |
apache / http_server | 2.0.45 | 2.0.45.x |
apache / http_server | 2.0.40 | 2.0.40.x |
apache / http_server | 2.0.43 | 2.0.43.x |