← All CVEs

CVE-2015-0228

medium · 5

The lua_websocket_read function in lua_request.c in the mod_lua module in the Apache HTTP Server through 2.4.12 allows remote attackers to cause a denial of service (child-process crash) by sending a crafted WebSocket Ping frame after a Lua script has called the wsupgrade function.

5
CVSS
16.5%
EPSS (exploit prob.)
97th
EPSS percentile
2015-03-08
Published

AV:N/AC:L/Au:N/C:N/I:N/A:P

Weaknesses

CWE-20

Affected products

VendorProductAffected versions
apachehttp_server<= 2.4.12
canonicalubuntu_linux10.04
canonicalubuntu_linux12.04
canonicalubuntu_linux14.04
canonicalubuntu_linux14.10
applemac_os_x10.10.4
applemac_os_x_server5.0.3
opensuseopensuse13.2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2015-0228