CVE Database
/

CVE-2015-0228

Back to search

CVE-2015-0228

Published: Mar 8, 2015

Modified: Aug 6, 2024

PUBLISHED

Description

The lua_websocket_read function in lua_request.c in the mod_lua module in the Apache HTTP Server through 2.4.12 allows remote attackers to cause a denial of service (child-process crash) by sending a crafted WebSocket Ping frame after a Lua script has called the wsupgrade function.

VendorProductVersions

n/a

n/a

affected
n/a

References

openSUSE-SU-2015:0418
vendor-advisory
x_refsource_SUSE
USN-2523-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2015:1666
vendor-advisory
x_refsource_REDHAT
1032967
vdb-entry
x_refsource_SECTRACK
APPLE-SA-2015-08-13-2
vendor-advisory
x_refsource_APPLE
91787
vdb-entry
x_refsource_BID
APPLE-SA-2015-09-16-4
vendor-advisory
x_refsource_APPLE
73041
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now