PT-2014-1433 · Apache+3 · Apache Http Server+3

Publicado

2014-07-15

·

Atualizado

2024-06-15

·

CVE-2014-0117

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.4.6 through 2.4.9
Description The issue allows remote attackers to cause a denial of service, resulting in the child process crashing when a specially crafted HTTP Connection header is sent to a server configured as a reverse proxy. This could lead to a denial of service against a threaded MPM.
Recommendations For Apache HTTP Server versions 2.4.6 through 2.4.9, update to version 2.4.10 or later to resolve the issue. As a temporary workaround, consider restricting access to the mod proxy module until a patch is available.

Correção

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-00395
CESA-2014_0921
CVE-2014-0117
MGASA-2014-0305
OPENSUSE-SU-2024:10268-1
RHSA-2014:0921
RHSA-2014:0922
RHSA-2014_0921
USN-2299-1
ZDI-14-239

Produtos afetados

Apache Http Server
Centos
Red Hat
Ubuntu