Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-0226

Опубликовано: 20 июл. 2014
Источник: ubuntu
Приоритет: medium
EPSS Критический
CVSS2: 6.8

Описание

Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service (heap-based buffer overflow), or possibly obtain sensitive credential information or execute arbitrary code, via a crafted request that triggers improper scoreboard handling within the status_handler function in modules/generators/mod_status.c and the lua_ap_scoreboard_worker function in modules/lua/lua_request.c.

РелизСтатусПримечание
devel

released

2.4.10-1ubuntu1
esm-infra-legacy/trusty

not-affected

2.4.7-1ubuntu4.1
lucid

released

2.2.14-5ubuntu8.14
precise

released

2.2.22-1ubuntu1.7
trusty

released

2.4.7-1ubuntu4.1
trusty/esm

not-affected

2.4.7-1ubuntu4.1
upstream

released

2.4.10

Показывать по

EPSS

Процентиль: 100%
0.90264
Критический

6.8 Medium

CVSS2

Связанные уязвимости

redhat
около 11 лет назад

Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service (heap-based buffer overflow), or possibly obtain sensitive credential information or execute arbitrary code, via a crafted request that triggers improper scoreboard handling within the status_handler function in modules/generators/mod_status.c and the lua_ap_scoreboard_worker function in modules/lua/lua_request.c.

nvd
около 11 лет назад

Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service (heap-based buffer overflow), or possibly obtain sensitive credential information or execute arbitrary code, via a crafted request that triggers improper scoreboard handling within the status_handler function in modules/generators/mod_status.c and the lua_ap_scoreboard_worker function in modules/lua/lua_request.c.

debian
около 11 лет назад

Race condition in the mod_status module in the Apache HTTP Server befo ...

github
больше 3 лет назад

Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service (heap-based buffer overflow), or possibly obtain sensitive credential information or execute arbitrary code, via a crafted request that triggers improper scoreboard handling within the status_handler function in modules/generators/mod_status.c and the lua_ap_scoreboard_worker function in modules/lua/lua_request.c.

fstec
около 11 лет назад

Уязвимость программного обеспечения Apache HTTP Server, позволяющая удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 100%
0.90264
Критический

6.8 Medium

CVSS2