PT-2014-1433 · Apache+3 · Apache Http Server+3

Published

2014-07-15

·

Updated

2024-06-15

·

CVE-2014-0117

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.4.6 through 2.4.9
Description The issue allows remote attackers to cause a denial of service, resulting in the child process crashing when a specially crafted HTTP Connection header is sent to a server configured as a reverse proxy. This could lead to a denial of service against a threaded MPM.
Recommendations For Apache HTTP Server versions 2.4.6 through 2.4.9, update to version 2.4.10 or later to resolve the issue. As a temporary workaround, consider restricting access to the mod proxy module until a patch is available.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-00395
CESA-2014_0921
CVE-2014-0117
MGASA-2014-0305
OPENSUSE-SU-2024:10268-1
RHSA-2014:0921
RHSA-2014:0922
RHSA-2014_0921
USN-2299-1
ZDI-14-239

Affected Products

Apache Http Server
Centos
Red Hat
Ubuntu