Описание
The deflate_in_filter function in mod_deflate.c in the mod_deflate module in the Apache HTTP Server before 2.4.10, when request body decompression is enabled, allows remote attackers to cause a denial of service (resource consumption) via crafted request data that decompresses to a much larger size.
A denial of service flaw was found in the way httpd's mod_deflate module handled request body decompression (configured via the "DEFLATE" input filter). A remote attacker able to send a request whose body would be decompressed could use this flaw to consume an excessive amount of system memory and CPU on the target system.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Directory Server 8 | httpd | Under investigation | ||
Red Hat JBoss Enterprise Application Platform 5 | httpd | Not affected | ||
Red Hat JBoss Enterprise Web Server 1 | httpd | Will not fix | ||
Red Hat JBoss Enterprise Web Server 1 | others | Not affected | ||
Red Hat Enterprise Linux 5 | httpd | Fixed | RHSA-2014:0920 | 23.07.2014 |
Red Hat Enterprise Linux 6 | httpd | Fixed | RHSA-2014:0920 | 23.07.2014 |
Red Hat Enterprise Linux 7 | httpd | Fixed | RHSA-2014:0921 | 23.07.2014 |
Red Hat JBoss Enterprise Application Platform 6.3 | httpd | Fixed | RHSA-2014:1021 | 06.08.2014 |
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5 | apache-commons-beanutils-eap6 | Fixed | RHSA-2014:1019 | 06.08.2014 |
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5 | apache-commons-cli-eap6 | Fixed | RHSA-2014:1019 | 06.08.2014 |
Показывать по
Дополнительная информация
Статус:
EPSS
5 Medium
CVSS2
Связанные уязвимости
The deflate_in_filter function in mod_deflate.c in the mod_deflate module in the Apache HTTP Server before 2.4.10, when request body decompression is enabled, allows remote attackers to cause a denial of service (resource consumption) via crafted request data that decompresses to a much larger size.
The deflate_in_filter function in mod_deflate.c in the mod_deflate module in the Apache HTTP Server before 2.4.10, when request body decompression is enabled, allows remote attackers to cause a denial of service (resource consumption) via crafted request data that decompresses to a much larger size.
The deflate_in_filter function in mod_deflate.c in the mod_deflate mod ...
The deflate_in_filter function in mod_deflate.c in the mod_deflate module in the Apache HTTP Server before 2.4.10, when request body decompression is enabled, allows remote attackers to cause a denial of service (resource consumption) via crafted request data that decompresses to a much larger size.
Уязвимость программного обеспечения Apache HTTP Server, позволяющая удаленному злоумышленнику нарушить доступность защищаемой информации
EPSS
5 Medium
CVSS2