Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-0118

Опубликовано: 17 июл. 2014
Источник: redhat
CVSS2: 5
EPSS Средний

Описание

The deflate_in_filter function in mod_deflate.c in the mod_deflate module in the Apache HTTP Server before 2.4.10, when request body decompression is enabled, allows remote attackers to cause a denial of service (resource consumption) via crafted request data that decompresses to a much larger size.

A denial of service flaw was found in the way httpd's mod_deflate module handled request body decompression (configured via the "DEFLATE" input filter). A remote attacker able to send a request whose body would be decompressed could use this flaw to consume an excessive amount of system memory and CPU on the target system.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Directory Server 8httpdUnder investigation
Red Hat JBoss Enterprise Application Platform 5httpdNot affected
Red Hat JBoss Enterprise Web Server 1httpdWill not fix
Red Hat JBoss Enterprise Web Server 1othersNot affected
Red Hat Enterprise Linux 5httpdFixedRHSA-2014:092023.07.2014
Red Hat Enterprise Linux 6httpdFixedRHSA-2014:092023.07.2014
Red Hat Enterprise Linux 7httpdFixedRHSA-2014:092123.07.2014
Red Hat JBoss Enterprise Application Platform 6.3httpdFixedRHSA-2014:102106.08.2014
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5apache-commons-beanutils-eap6FixedRHSA-2014:101906.08.2014
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5apache-commons-cli-eap6FixedRHSA-2014:101906.08.2014

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1120601httpd: mod_deflate denial of service

EPSS

Процентиль: 98%
0.49074
Средний

5 Medium

CVSS2

Связанные уязвимости

ubuntu
около 11 лет назад

The deflate_in_filter function in mod_deflate.c in the mod_deflate module in the Apache HTTP Server before 2.4.10, when request body decompression is enabled, allows remote attackers to cause a denial of service (resource consumption) via crafted request data that decompresses to a much larger size.

nvd
около 11 лет назад

The deflate_in_filter function in mod_deflate.c in the mod_deflate module in the Apache HTTP Server before 2.4.10, when request body decompression is enabled, allows remote attackers to cause a denial of service (resource consumption) via crafted request data that decompresses to a much larger size.

debian
около 11 лет назад

The deflate_in_filter function in mod_deflate.c in the mod_deflate mod ...

github
больше 3 лет назад

The deflate_in_filter function in mod_deflate.c in the mod_deflate module in the Apache HTTP Server before 2.4.10, when request body decompression is enabled, allows remote attackers to cause a denial of service (resource consumption) via crafted request data that decompresses to a much larger size.

fstec
около 11 лет назад

Уязвимость программного обеспечения Apache HTTP Server, позволяющая удаленному злоумышленнику нарушить доступность защищаемой информации

EPSS

Процентиль: 98%
0.49074
Средний

5 Medium

CVSS2

Уязвимость CVE-2014-0118