Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-0098

Опубликовано: 07 мар. 2014
Источник: redhat
CVSS2: 4.3

Описание

The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a denial of service (segmentation fault and daemon crash) via a crafted cookie that is not properly handled during truncation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Directory Server 8httpdNot affected
Red Hat Enterprise Linux 7httpdNot affected
Red Hat JBoss Enterprise Application Platform 5httpdWill not fix
Red Hat JBoss Enterprise Web Server 1httpdWill not fix
Red Hat JBoss Enterprise Web Server 1othersNot affected
Red Hat Software Collectionshttpd24-httpdAffected
Red Hat Enterprise Linux 5httpdFixedRHSA-2014:036903.04.2014
Red Hat Enterprise Linux 6httpdFixedRHSA-2014:037003.04.2014
Red Hat JBoss Enterprise Application Platform 6.2FixedRHSA-2014:082501.07.2014
Red Hat JBoss Enterprise Application Platform 6.2 for RHEL 5httpdFixedRHSA-2014:082601.07.2014

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-228->CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1077871httpd: mod_log_config does not properly handle logging certain cookies resulting in DoS

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 11 лет назад

The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a denial of service (segmentation fault and daemon crash) via a crafted cookie that is not properly handled during truncation.

nvd
больше 11 лет назад

The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a denial of service (segmentation fault and daemon crash) via a crafted cookie that is not properly handled during truncation.

debian
больше 11 лет назад

The log_cookie function in mod_log_config.c in the mod_log_config modu ...

github
больше 3 лет назад

The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a denial of service (segmentation fault and daemon crash) via a crafted cookie that is not properly handled during truncation.

oracle-oval
больше 11 лет назад

ELSA-2014-0370: httpd security update (MODERATE)

4.3 Medium

CVSS2