{"id":"CVE-2012-3526","details":"The reverse proxy add forward module (mod_rpaf) 0.5 and 0.6 for the Apache HTTP Server allows remote attackers to cause a denial of service (server or application crash) via multiple X-Forwarded-For headers in a request.","modified":"2026-04-10T03:42:24.724110Z","published":"2012-09-05T23:55:01Z","references":[{"type":"ADVISORY","url":"http://secunia.com/advisories/50400"},{"type":"ADVISORY","url":"http://www.debian.org/security/2012/dsa-2532"},{"type":"WEB","url":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=683984"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2012/08/22/2"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2012/08/22/7"},{"type":"WEB","url":"http://www.securityfocus.com/bid/55154"},{"type":"WEB","url":"http://zecrazytux.net/troubleshooting/apache2-segfault-debugging-tutorial"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/77987"}],"schema_version":"1.7.5"}