Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-0231

Опубликовано: 17 июл. 2014
Источник: redhat
CVSS2: 5
EPSS Средний

Описание

The mod_cgid module in the Apache HTTP Server before 2.4.10 does not have a timeout mechanism, which allows remote attackers to cause a denial of service (process hang) via a request to a CGI script that does not read from its stdin file descriptor.

A denial of service flaw was found in the way httpd's mod_cgid module executed CGI scripts that did not read data from the standard input. A remote attacker could submit a specially crafted request that would cause the httpd child process to hang indefinitely.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Directory Server 8httpdUnder investigation
Red Hat JBoss Enterprise Application Platform 5httpdNot affected
Red Hat JBoss Enterprise Web Server 1httpdWill not fix
Red Hat JBoss Enterprise Web Server 1othersNot affected
Red Hat Enterprise Linux 5httpdFixedRHSA-2014:092023.07.2014
Red Hat Enterprise Linux 6httpdFixedRHSA-2014:092023.07.2014
Red Hat Enterprise Linux 7httpdFixedRHSA-2014:092123.07.2014
Red Hat JBoss Enterprise Application Platform 6.3httpdFixedRHSA-2014:102106.08.2014
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5apache-commons-beanutils-eap6FixedRHSA-2014:101906.08.2014
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5apache-commons-cli-eap6FixedRHSA-2014:101906.08.2014

Показывать по

Дополнительная информация

Статус:

Moderate

EPSS

Процентиль: 95%
0.17169
Средний

5 Medium

CVSS2

Связанные уязвимости

ubuntu
около 11 лет назад

The mod_cgid module in the Apache HTTP Server before 2.4.10 does not have a timeout mechanism, which allows remote attackers to cause a denial of service (process hang) via a request to a CGI script that does not read from its stdin file descriptor.

nvd
около 11 лет назад

The mod_cgid module in the Apache HTTP Server before 2.4.10 does not have a timeout mechanism, which allows remote attackers to cause a denial of service (process hang) via a request to a CGI script that does not read from its stdin file descriptor.

debian
около 11 лет назад

The mod_cgid module in the Apache HTTP Server before 2.4.10 does not h ...

github
больше 3 лет назад

The mod_cgid module in the Apache HTTP Server before 2.4.10 does not have a timeout mechanism, which allows remote attackers to cause a denial of service (process hang) via a request to a CGI script that does not read from its stdin file descriptor.

fstec
около 11 лет назад

Уязвимость программного обеспечения Apache HTTP Server, позволяющая удаленному злоумышленнику нарушить доступность защищаемой информации

EPSS

Процентиль: 95%
0.17169
Средний

5 Medium

CVSS2

Уязвимость CVE-2014-0231