PT-2014-1438 · Apache+2 · Apache Http Server+2

Murray Mcallister

·

Publicado

2014-07-14

·

Atualizado

2021-06-06

·

CVE-2013-4352

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.4.6
Description The issue is related to a function cache invalidate in the mod cache module. It allows remote HTTP servers to cause a denial of service, resulting in a daemon crash due to a NULL pointer dereference. This occurs when a caching forward proxy is enabled and a missing hostname value is triggered. The estimated number of potentially affected devices is not provided.
Recommendations For Apache HTTP Server version 2.4.6, update to version 2.4.7 or later to resolve the issue. As a temporary workaround, consider disabling the cache invalidate function in the mod cache module until a patch is available. Restrict access to the caching forward proxy configuration to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-00400
CESA-2014_0921
CVE-2013-4352
RHSA-2014:0921
RHSA-2014:0922
RHSA-2014_0921

Produtos afetados

Apache Http Server
Centos
Red Hat