← All CVEs

CVE-2014-3583

medium · 5

The handle_headers function in mod_proxy_fcgi.c in the mod_proxy_fcgi module in the Apache HTTP Server 2.4.10 allows remote FastCGI servers to cause a denial of service (buffer over-read and daemon crash) via long response headers.

5
CVSS
10.8%
EPSS (exploit prob.)
96th
EPSS percentile
2014-12-15
Published

AV:N/AC:L/Au:N/C:N/I:N/A:P

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
applemac_os_x10.9.5
applemac_os_x10.10.0
applemac_os_x10.10.1
applemac_os_x10.10.2
applemac_os_x10.10.3
applemac_os_x10.10.4
appleos_x_server5.0.3
apachehttp_server2.4.10
canonicalubuntu_linux10.04
canonicalubuntu_linux12.04
canonicalubuntu_linux14.04
canonicalubuntu_linux14.10

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2014-3583