Описание
The mod_cgid module in the Apache HTTP Server before 2.4.10 does not have a timeout mechanism, which allows remote attackers to cause a denial of service (process hang) via a request to a CGI script that does not read from its stdin file descriptor.
A denial of service flaw was found in the way httpd's mod_cgid module executed CGI scripts that did not read data from the standard input. A remote attacker could submit a specially crafted request that would cause the httpd child process to hang indefinitely.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Directory Server 8 | httpd | Under investigation | ||
Red Hat JBoss Enterprise Application Platform 5 | httpd | Not affected | ||
Red Hat JBoss Enterprise Web Server 1 | httpd | Will not fix | ||
Red Hat JBoss Enterprise Web Server 1 | others | Not affected | ||
Red Hat Enterprise Linux 5 | httpd | Fixed | RHSA-2014:0920 | 23.07.2014 |
Red Hat Enterprise Linux 6 | httpd | Fixed | RHSA-2014:0920 | 23.07.2014 |
Red Hat Enterprise Linux 7 | httpd | Fixed | RHSA-2014:0921 | 23.07.2014 |
Red Hat JBoss Enterprise Application Platform 6.3 | httpd | Fixed | RHSA-2014:1021 | 06.08.2014 |
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5 | apache-commons-beanutils-eap6 | Fixed | RHSA-2014:1019 | 06.08.2014 |
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5 | apache-commons-cli-eap6 | Fixed | RHSA-2014:1019 | 06.08.2014 |
Показывать по
Дополнительная информация
Статус:
EPSS
5 Medium
CVSS2
Связанные уязвимости
The mod_cgid module in the Apache HTTP Server before 2.4.10 does not have a timeout mechanism, which allows remote attackers to cause a denial of service (process hang) via a request to a CGI script that does not read from its stdin file descriptor.
The mod_cgid module in the Apache HTTP Server before 2.4.10 does not have a timeout mechanism, which allows remote attackers to cause a denial of service (process hang) via a request to a CGI script that does not read from its stdin file descriptor.
The mod_cgid module in the Apache HTTP Server before 2.4.10 does not h ...
The mod_cgid module in the Apache HTTP Server before 2.4.10 does not have a timeout mechanism, which allows remote attackers to cause a denial of service (process hang) via a request to a CGI script that does not read from its stdin file descriptor.
Уязвимость программного обеспечения Apache HTTP Server, позволяющая удаленному злоумышленнику нарушить доступность защищаемой информации
EPSS
5 Medium
CVSS2