CVE-2009-2699 describes a denial-of-service vulnerability in the Apache Portable Runtime (APR) library, specifically affecting the Solaris pollset feature, which is used by Apache HTTP Server and other products. This flaw, rated High severity (CVSS 7.5), allows remote attackers to cause a daemon hang through unspecified HTTP requests due to improper error handling. While the vulnerability has a high risk score, there is no evidence of active exploitation, public exploit code, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.2.0, < 2.2.14CPE matchmatch criteria | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* | ||
< 1.3.9CPE matchmatch criteria | cpe:2.3:a:apache:portable_runtime:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.