PT-2014-1438 · Apache+2 · Apache Http Server+2
Murray Mcallister
·
Publicado
2014-07-14
·
Atualizado
2021-06-06
·
CVE-2013-4352
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Apache HTTP Server versions 2.4.6
Description
The issue is related to a function
cache invalidate in the mod cache module. It allows remote HTTP servers to cause a denial of service, resulting in a daemon crash due to a NULL pointer dereference. This occurs when a caching forward proxy is enabled and a missing hostname value is triggered. The estimated number of potentially affected devices is not provided.Recommendations
For Apache HTTP Server version 2.4.6, update to version 2.4.7 or later to resolve the issue. As a temporary workaround, consider disabling the
cache invalidate function in the mod cache module until a patch is available. Restrict access to the caching forward proxy configuration to minimize the risk of exploitation.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Apache Http Server
Centos
Red Hat