Vulnerability record · CVE-2004-0493 · published 6 August 2004
CVE-2004-0493: Apache httpd header parsing flaw causes memory exhaustion and possible heap overflow
Avaya · Converged Communications Server
The ap_get_mime_headers_core function in Apache httpd 2.0.49 mishandles long header lines containing many space or tab characters, causing memory exhaustion. The same input may trigger an integer signedness error leading to a heap-based buffer overflow on 64-bit systems. It matters because a remote, unauthenticated request can degrade or crash the service, with a possible code execution path on 64-bit builds.
Description
The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memory exhaustion), and possibly an integer signedness error leading to a heap-based buffer overflow on 64 bit systems, via long header lines with large numbers of space or tab characters.
AV:N/AC:L/Au:N/C:N/I:P/A:P
Automated analysis
high priorityRemote unauthenticated denial of service with a possible heap overflow on 64-bit systems, plus very high EPSS and a public exploit reference, outweigh the dated medium CVSS v2 score.
What it is
The ap_get_mime_headers_core function in Apache httpd 2.0.49 mishandles long header lines containing many space or tab characters, causing memory exhaustion. The same input may trigger an integer signedness error leading to a heap-based buffer overflow on 64-bit systems. It matters because a remote, unauthenticated request can degrade or crash the service, with a possible code execution path on 64-bit builds.
Impact
An attacker can exhaust server memory to cause denial of service, and on 64-bit systems may corrupt the heap, potentially leading to code execution in the httpd process context. No confidentiality impact is stated in the CVSS vector.
Attack surface
Reached remotely over the network by sending HTTP requests with crafted long header lines; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.848, 99.7th percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit activity exists.
What to do
- Upgrade Apache httpd to a version later than 2.0.49 that contains the fix, or apply the vendor patch referenced in the Apache and distribution advisories.
- Apply the relevant vendor updates for bundled httpd in Avaya, Gentoo, Trustix, IBM and Mandriva products.
- Enforce strict request header size limits at the reverse proxy or web server (LimitRequestFieldSize, LimitRequestLine) to cap oversized header lines.
- Restrict or rate-limit untrusted HTTP traffic to exposed httpd instances to reduce the impact of memory exhaustion attempts.
Detection
- Monitor httpd memory usage and process restarts for abnormal growth correlated with large or malformed request headers.
- Alert on requests containing unusually long header lines or long runs of space and tab characters in headers.
- Review web server and proxy logs for repeated oversized-header requests from single sources.
- Use network IDS signatures for the known public exploit for this issue.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2004-0493 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2004-0493), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.