PT-2014-1438 · Apache+2 · Apache Http Server+2
Murray Mcallister
·
Published
2014-07-14
·
Updated
2021-06-06
·
CVE-2013-4352
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Apache HTTP Server versions 2.4.6
Description
The issue is related to a function
cache invalidate in the mod cache module. It allows remote HTTP servers to cause a denial of service, resulting in a daemon crash due to a NULL pointer dereference. This occurs when a caching forward proxy is enabled and a missing hostname value is triggered. The estimated number of potentially affected devices is not provided.Recommendations
For Apache HTTP Server version 2.4.6, update to version 2.4.7 or later to resolve the issue. As a temporary workaround, consider disabling the
cache invalidate function in the mod cache module until a patch is available. Restrict access to the caching forward proxy configuration to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Http Server
Centos
Red Hat