CVE-2014-0098
medium · 5The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a denial of service (segmentation fault and daemon crash) via a crafted cookie that is not properly handled during truncation.
5
CVSS
26.0%
EPSS (exploit prob.)
98th
EPSS percentile
2014-03-18
Published
AV:N/AC:L/Au:N/C:N/I:N/A:P
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apache | http_server | >= 2.2.0, < 2.2.27 |
| apache | http_server | >= 2.4.1, < 2.4.9 |
| oracle | http_server | 10.1.3.5.0 |
| oracle | http_server | 11.1.1.7.0 |
| oracle | http_server | 12.1.2.0 |
| oracle | http_server | 12.1.3.0 |
| oracle | secure_global_desktop | 4.63 |
| oracle | secure_global_desktop | 4.71 |
| oracle | secure_global_desktop | 5.0 |
| oracle | secure_global_desktop | 5.1 |
| canonical | ubuntu_linux | 10.04 |
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 12.10 |
| canonical | ubuntu_linux | 13.10 |
Check a specific version with /api/v1/cve/match.
References
- http://advisories.mageia.org/MGASA-2014-0135.html
- http://archives.neohapsis.com/archives/bugtraq/2014-10/0101.html
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10698
- http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.html
- http://marc.info/?l=bugtraq&m=141017844705317&w=2
- http://marc.info/?l=bugtraq&m=141390017113542&w=2
- http://seclists.org/fulldisclosure/2014/Dec/23
- http://secunia.com/advisories/58230
- http://secunia.com/advisories/58915
- http://secunia.com/advisories/59219
- http://secunia.com/advisories/59315
- http://secunia.com/advisories/59345
- http://secunia.com/advisories/60536
- http://security.gentoo.org/glsa/glsa-201408-12.xml
- http://support.f5.com/kb/en-us/solutions/public/15000/300/sol15320.html
- http://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x/CHANGES
- http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/loggers/mod_log_config.c
- http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/loggers/mod_log_config.c?r1=1575394&r2=1575400&diff_format=h
- http://www-01.ibm.com/support/docview.wss?uid=swg21668973
- http://www-01.ibm.com/support/docview.wss?uid=swg21676091
- http://www-01.ibm.com/support/docview.wss?uid=swg21676092
- http://www.apache.org/dist/httpd/CHANGES_2.4.9
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html
- http://www.securityfocus.com/archive/1/534161/100/0/threaded
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2014-0098