CVE-2014-0117

Published Jul 20, 2014

Last updated a year ago

Overview

Description
The mod_proxy module in the Apache HTTP Server 2.4.x before 2.4.10, when a reverse proxy is enabled, allows remote attackers to cause a denial of service (child-process crash) via a crafted HTTP Connection header.
Source
secalert@redhat.com
NVD status
Modified

Social media

Hype score
Not currently trending

Risk scores

CVSS 2.0

Type
Primary
Base score
4.3
Impact score
2.9
Exploitability score
8.6
Vector string
AV:N/AC:M/Au:N/C:N/I:N/A:P

Weaknesses

nvd@nist.gov
CWE-20

Evaluator

Comment
Per vendor advisory http://httpd.apache.org/security/vulnerabilities_24.html "A flaw was found in mod_proxy in httpd versions 2.4.6 to 2.4.9."
Impact
-
Solution
-

Configurations

References