PT-2014-1434 · Apache+6 · Apache Http Server+6

Publicado

2014-07-14

·

Atualizado

2024-06-15

·

CVE-2014-0226

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions prior to 2.4.10
Description A race condition in the mod status module allows remote attackers to cause a denial of service, obtain sensitive credential information, or execute arbitrary code via a crafted request that triggers improper scoreboard handling within the status handler function in modules/generators/mod status.c and the lua ap scoreboard worker function in modules/lua/lua request.c. This issue can be exploited by sending a carefully crafted request to a public server status page on a server using a threaded MPM.
Recommendations For Apache HTTP Server versions prior to 2.4.10, update to version 2.4.10 or later to resolve the issue. As a temporary workaround, consider restricting access to the server status page to minimize the risk of exploitation. Additionally, disabling the mod status module can prevent the issue until a patch is applied.

Exploit

Correção

DoS

Race Condition

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2015-1890
BDU:2015-00396
CESA-2014_0920
CESA-2014_0921
CVE-2014-0226
DLA-66-1
DSA-2989-1
HPSBUX03337
HPSBUX03512
MGASA-2014-0304
MGASA-2014-0305
OPENSUSE-SU-2014_0969-1
OPENSUSE-SU-2024:10268-1
RHSA-2014:0920
RHSA-2014:0921
RHSA-2014:0922
RHSA-2014:1019
RHSA-2014:1020
RHSA-2014:1087
RHSA-2014:1088
RHSA-2014_0920
RHSA-2014_0921
SUSE-SU-2015:0689-1
USN-2299-1
ZDI-14-236

Produtos afetados

Alt Linux
Apache Http Server
Centos
Hp-Ux
Red Hat
Suse
Ubuntu