Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-0242

Опубликовано: 21 мая 2014
Источник: redhat
CVSS2: 5

Описание

mod_wsgi module before 3.4 for Apache, when used in embedded mode, might allow remote attackers to obtain sensitive information via the Content-Type header which is generated from memory that may have been freed and then overwritten by a separate thread.

Отчет

Red Hat Update Infrastructure 2.1.3 is now in Production 2 Phase of the support and maintenance life cycle. This has been rated as having Moderate security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Update Infrastructure Life Cycle: https://access.redhat.com/support/policy/updates/rhui.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7mod_wsgiNot affected
Red Hat OpenShift Enterprise 2python27-mod_wsgiNot affected
Red Hat Satellite 5.6mod_wsgiWill not fix
Red Hat Satellite 6mod_wsgiNot affected
Red Hat Satellite Proxy 5.6mod_wsgiWill not fix
Red Hat Software Collectionspython27-mod_wsgiNot affected
Red Hat Software Collectionspython33-mod_wsgiNot affected
Red Hat Subscription Asset Managermod_wsgiNot affected
RHUI for RHEL 6mod_wsgiWill not fix
Red Hat Enterprise Linux 6mod_wsgiFixedRHSA-2014:078825.06.2014

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-200

5 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 5 лет назад

mod_wsgi module before 3.4 for Apache, when used in embedded mode, might allow remote attackers to obtain sensitive information via the Content-Type header which is generated from memory that may have been freed and then overwritten by a separate thread.

CVSS3: 7.5
nvd
больше 5 лет назад

mod_wsgi module before 3.4 for Apache, when used in embedded mode, might allow remote attackers to obtain sensitive information via the Content-Type header which is generated from memory that may have been freed and then overwritten by a separate thread.

CVSS3: 7.5
debian
больше 5 лет назад

mod_wsgi module before 3.4 for Apache, when used in embedded mode, mig ...

CVSS3: 7.5
github
больше 3 лет назад

mod_wsgi module before 3.4 for Apache, when used in embedded mode, might allow remote attackers to obtain sensitive information via the Content-Type header which is generated from memory that may have been freed and then overwritten by a separate thread.

oracle-oval
около 11 лет назад

ELSA-2014-0788: mod_wsgi security update (IMPORTANT)

5 Medium

CVSS2