CVE Database
/

CVE-2014-0226

Back to search

CVE-2014-0226

Published: Jul 20, 2014

Modified: Aug 6, 2024

PUBLISHED

Description

Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service (heap-based buffer overflow), or possibly obtain sensitive credential information or execute arbitrary code, via a crafted request that triggers improper scoreboard handling within the status_handler function in modules/generators/mod_status.c and the lua_ap_scoreboard_worker function in modules/lua/lua_request.c.

VendorProductVersions

n/a

n/a

affected
n/a

References

HPSBUX03512
vendor-advisory
x_refsource_HP
DSA-2989
vendor-advisory
x_refsource_DEBIAN
68678
vdb-entry
x_refsource_BID
HPSBMU03409
vendor-advisory
x_refsource_HP
GLSA-201408-12
vendor-advisory
x_refsource_GENTOO
GLSA-201504-03
vendor-advisory
x_refsource_GENTOO
RHSA-2014:1020
vendor-advisory
x_refsource_REDHAT
60536
third-party-advisory
x_refsource_SECUNIA
HPSBMU03380
vendor-advisory
x_refsource_HP
SSRT102066
vendor-advisory
x_refsource_HP
RHSA-2014:1021
vendor-advisory
x_refsource_REDHAT
SSRT102254
vendor-advisory
x_refsource_HP
APPLE-SA-2015-04-08-2
vendor-advisory
x_refsource_APPLE
MDVSA-2014:142
vendor-advisory
x_refsource_MANDRIVA
RHSA-2014:1019
vendor-advisory
x_refsource_REDHAT
109216
vdb-entry
x_refsource_OSVDB
34133
exploit
x_refsource_EXPLOIT-DB
HPSBUX03337
vendor-advisory
x_refsource_HP

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now