PT-2014-1434 · Apache+6 · Apache Http Server+6

Published

2014-07-14

·

Updated

2024-06-15

·

CVE-2014-0226

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions prior to 2.4.10
Description A race condition in the mod status module allows remote attackers to cause a denial of service, obtain sensitive credential information, or execute arbitrary code via a crafted request that triggers improper scoreboard handling within the status handler function in modules/generators/mod status.c and the lua ap scoreboard worker function in modules/lua/lua request.c. This issue can be exploited by sending a carefully crafted request to a public server status page on a server using a threaded MPM.
Recommendations For Apache HTTP Server versions prior to 2.4.10, update to version 2.4.10 or later to resolve the issue. As a temporary workaround, consider restricting access to the server status page to minimize the risk of exploitation. Additionally, disabling the mod status module can prevent the issue until a patch is applied.

Exploit

Fix

DoS

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1890
BDU:2015-00396
CESA-2014_0920
CESA-2014_0921
CVE-2014-0226
DLA-66-1
DSA-2989-1
HPSBUX03337
HPSBUX03512
MGASA-2014-0304
MGASA-2014-0305
OPENSUSE-SU-2014_0969-1
OPENSUSE-SU-2024:10268-1
RHSA-2014:0920
RHSA-2014:0921
RHSA-2014:0922
RHSA-2014:1019
RHSA-2014:1020
RHSA-2014:1087
RHSA-2014:1088
RHSA-2014_0920
RHSA-2014_0921
SUSE-SU-2015:0689-1
USN-2299-1
ZDI-14-236

Affected Products

Alt Linux
Apache Http Server
Centos
Hp-Ux
Red Hat
Suse
Ubuntu