PT-2014-1438 · Apache+2 · Apache Http Server+2

Murray Mcallister

·

Published

2014-07-14

·

Updated

2021-06-06

·

CVE-2013-4352

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.4.6
Description The issue is related to a function cache invalidate in the mod cache module. It allows remote HTTP servers to cause a denial of service, resulting in a daemon crash due to a NULL pointer dereference. This occurs when a caching forward proxy is enabled and a missing hostname value is triggered. The estimated number of potentially affected devices is not provided.
Recommendations For Apache HTTP Server version 2.4.6, update to version 2.4.7 or later to resolve the issue. As a temporary workaround, consider disabling the cache invalidate function in the mod cache module until a patch is available. Restrict access to the caching forward proxy configuration to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-00400
CESA-2014_0921
CVE-2013-4352
RHSA-2014:0921
RHSA-2014:0922
RHSA-2014_0921

Affected Products

Apache Http Server
Centos
Red Hat