5
CVSSv2

CVE-2004-2680

Published: 31/12/2004 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

mod_python (libapache2-mod-python) 3.1.4 and previous versions does not properly handle when output filters process more than 16384 bytes, which can cause filter.read to return portions of previously freed memory.

Vulnerable Product Search on Vulmon Subscribe to Product

apache mod python

Vendor Advisories

Miles Egan discovered that mod_python, when used in output filter mode, did not handle output larger than 16384 bytes, and would display freed memory, possibly disclosing private data Thanks to Jim Garrison of the Software Freedom Law Center for identifying the original bug as a security vulnerability ...