CVE-2014-0098
published 2014-03-18CVE-2014-0098: The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a denial of…
PriorityP334medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
26.00%
97.8th percentile
The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a denial of service (segmentation fault and daemon crash) via a crafted cookie that is not properly handled during truncation.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | >= 2.2.0 < 2.2.27 | 2.2.27 |
| apache | http_server | >= 2.4.1 < 2.4.9 | 2.4.9 |
| apache | httpd | — | — |
| apple | os_x_yosemite_v10.10.3_and_security_update_2015-004 | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | apache2 | < apache2 2.4.9-1 (bookworm) | apache2 2.4.9-1 (bookworm) |
| oracle | http_server | — | — |
| oracle | http_server | — | — |
| oracle | http_server | — | — |
| oracle | http_server | — | — |
| oracle | secure_global_desktop | — | — |
| oracle | secure_global_desktop | — | — |
| oracle | secure_global_desktop | — | — |
| oracle | secure_global_desktop | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability is triggered by a malformed/truncated Cookie header in an HTTP request. Detection should focus on anomalous Cookie headers sent to Apache httpd servers running mod_log_config with cookie logging enabled (e.g., %{Foobar}C LogFormat directive). ↗
- →The crash only results in a denial of service when Apache is using a threaded MPM. Monitor for unexpected httpd child process crashes (segmentation faults) on servers using threaded MPMs with cookie logging configured. ↗
- →Affected Apache httpd versions span 2.2.0–2.2.26 and 2.4.1–2.4.7. Identify unpatched instances (pre-2.4.8 / pre-2.2.27) with mod_log_config loaded and cookie logging active as high-priority targets. ↗
- ·Only Apache httpd instances explicitly configured to log cookie values (using %{CookieName}C in LogFormat) are vulnerable. Default Red Hat Enterprise Linux configurations do not enable cookie logging and are therefore not affected. ↗
- ·Cookie logging can be disabled as a mitigation. Removing %{...}C format specifiers from LogFormat directives prevents exploitation. ↗
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_apache5.0LOW
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mfxf-5vhj-623g: The log_cookie function in mod_log_config
ghsa_unreviewed·2022-05-13
CVE-2014-0098 [MEDIUM] CWE-20 GHSA-mfxf-5vhj-623g: The log_cookie function in mod_log_config
The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a denial of service (segmentation fault and daemon crash) via a crafted cookie that is not properly handled during truncation.
OSV
CVE-2014-0098: The log_cookie function in mod_log_config
osv·2014-03-18·CVSS 5.0
CVE-2014-0098 [MEDIUM] CVE-2014-0098: The log_cookie function in mod_log_config
The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a denial of service (segmentation fault and daemon crash) via a crafted cookie that is not properly handled during truncation.
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2014-03-24·CVSS 5.0
CVE-2013-6438 [MEDIUM] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Apache HTTP server could be made to crash if it received specially crafted
network traffic.
Ning Zhang & Amin Tora discovered that the mod_dav module incorrectly
handled whitespace characters in CDATA sections. A remote attacker could
use this issue to cause the server to stop responding, resulting in a
denial of service. (CVE-2013-6438)
Rainer M Canavan discovered that the mod_log_config module incorrectly
handled certain cookies. A remote attacker could use this issue to cause
the server to stop responding, resulting in a denial of service. This issue
only affected Ubuntu 12.04 LTS, Ubuntu 12.10 and Ubuntu 13.10.
(CVE-2014-0098)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
httpd: mod_log_config does not properly handle logging certain cookies resulting in DoS
vendor_redhat·2014-03-07·CVSS 5.0
CVE-2014-0098 [MEDIUM] CWE-228 httpd: mod_log_config does not properly handle logging certain cookies resulting in DoS
httpd: mod_log_config does not properly handle logging certain cookies resulting in DoS
The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a denial of service (segmentation fault and daemon crash) via a crafted cookie that is not properly handled during truncation.
Package: httpd (Red Hat Directory Server 8) - Not affected
Package: httpd (Red Hat Enterprise Linux 7) - Not affected
Package: httpd (Red Hat JBoss Enterprise Application Platform 5) - Will not fix
Package: httpd (Red Hat JBoss Enterprise Web Server 1) - Will not fix
Package: httpd24-httpd (Red Hat Software Collections) - Affected
Debian
CVE-2014-0098: apache2 - The log_cookie function in mod_log_config.c in the mod_log_config module in the ...
vendor_debian·2014·CVSS 5.0
CVE-2014-0098 [MEDIUM] CVE-2014-0098: apache2 - The log_cookie function in mod_log_config.c in the mod_log_config module in the ...
The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a denial of service (segmentation fault and daemon crash) via a crafted cookie that is not properly handled during truncation.
Scope: local
bookworm: resolved (fixed in 2.4.9-1)
bullseye: resolved (fixed in 2.4.9-1)
forky: resolved (fixed in 2.4.9-1)
sid: resolved (fixed in 2.4.9-1)
trixie: resolved (fixed in 2.4.9-1)
Apple
CVE-2014-0098: OS X Yosemite v10.10.3 and Security Update 2015-004
vendor_apple·CVSS 5.0
CVE-2014-0098 [MEDIUM] CVE-2014-0098: OS X Yosemite v10.10.3 and Security Update 2015-004
Apple Security Update: About the security content of OS X Yosemite v10.10.3 and Security Update 2015-004
Product: OS X Yosemite v10.10.3 and Security Update 2015-004
CVE: CVE-2014-0098
Component: CVE-2014-0098
Apache
Apache httpd: CVE-2014-0098
vendor_apache·CVSS 5.0
CVE-2014-0098 [LOW] Apache httpd: CVE-2014-0098
Apache httpd: CVE-2014-0098
A flaw was found in mod_log_config. A remote attacker could send a specific truncated cookie causing a crash. This crash would only be a denial of service if using a threaded MPM. Acknowledgements: This issue was reported by Rainer M Canavan Reported to security team 2014-02-25 Issue public 2014-03-17 Update 2.4.9 released 2014-03-17 Update 2.2.27 released 2014-03-26 Affects 2.4.7, 2.4.6, 2.4.4, 2.4.3, 2.4.2, 2.4.1, 2.2.26, 2.2.25, 2.2.24, 2.2.23, 2.2.22, 2.2.21, 2.2.20, 2.2.19, 2.2.18, 2.2.17, 2.2.16, 2.2.15, 2.2.14, 2.2.13, 2.2.12, 2.2.11, 2.2.10, 2.2.9, 2.2.8, 2.2.6, 2.2.5, 2.2.4, 2.2.3, 2.2.2, 2.2.0
Severity: low
No detection rules found.
No public exploits indexed.
HackerOne
Out-of-date Version (Apache)
hackerone·2019-12-02·CVSS 5.0
[MEDIUM] Out-of-date Version (Apache)
Out-of-date Version (Apache)
URL https://████████/
Identified Version 2.2.15 (contains 4 important and 10 other vulnerabilities)
Latest Version 2.2.31
Vulnerability Database Result is based on 27.10.2016 vulnerability database content.
Vulnerability Details
Link identified you are using an out-of-date version of Apache.
Impact
Since this is an old version of the software, it may be vulnerable to attacks.
Remedy
Please upgrade your installation of Apache to the latest stable version.
Remedy References
•Downloading the Apache HTTP Server
Known Vulnerabilities in this Version
Medium Apache mod_cache and mod_dav Request Handling Denial of Service Vulnerability
The mod_cache and mod_dav modules in the Apache HTTP Server allow remote attackers to cause a denial of service (process
Bugzilla
CVE-2014-0098 httpd: mod_log_config does not properly handle logging certain cookies resulting in DoS
bugzilla·2014-03-18·CVSS 5.0
CVE-2014-0098 [MEDIUM] CVE-2014-0098 httpd: mod_log_config does not properly handle logging certain cookies resulting in DoS
CVE-2014-0098 httpd: mod_log_config does not properly handle logging certain cookies resulting in DoS
Common Vulnerabilities and Exposures assigned an identifier CVE-2014-0098 to
the following vulnerability:
Name: CVE-2014-0098
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0098
Assigned: 20131203
Reference: http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/loggers/mod_log_config.c
Reference: http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/loggers/mod_log_config.c?r1=1575394&r2=1575400&diff_format=h
Reference: http://www.apache.org/dist/httpd/CHANGES_2.4.9
The log_cookie function in mod_log_config.c in the mod_log_config
module in the Apache HTTP Server before 2.4.8 allows remote attackers
to cause a denial of service (segmentation fault and daemon crash) via
a
Bugzilla
CVE-2013-6438 CVE-2014-0098 httpd: various flaws [fedora-all]
bugzilla·2014-03-18·CVSS 5.0
CVE-2013-6438 [MEDIUM] CVE-2013-6438 CVE-2014-0098 httpd: various flaws [fedora-all]
CVE-2013-6438 CVE-2014-0098 httpd: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects multiple su
Tenable
[R6] SecurityCenter Affected by Multiple Third-party Library Vulnerabilities
blogs_tenable·2014-07-16
[R6] SecurityCenter Affected by Multiple Third-party Library Vulnerabilities
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
http://advisories.mageia.org/MGASA-2014-0135.htmlhttp://archives.neohapsis.com/archives/bugtraq/2014-10/0101.htmlhttp://kb.juniper.net/InfoCenter/index?page=content&id=JSA10698http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.htmlhttp://marc.info/?l=bugtraq&m=141017844705317&w=2http://marc.info/?l=bugtraq&m=141390017113542&w=2http://seclists.org/fulldisclosure/2014/Dec/23http://secunia.com/advisories/58230http://secunia.com/advisories/58915http://secunia.com/advisories/59219http://secunia.com/advisories/59315http://secunia.com/advisories/59345http://secunia.com/advisories/60536http://security.gentoo.org/glsa/glsa-201408-12.xmlhttp://support.f5.com/kb/en-us/solutions/public/15000/300/sol15320.htmlhttp://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x/CHANGEShttp://svn.apache.org/viewvc/httpd/httpd/trunk/modules/loggers/mod_log_config.chttp://svn.apache.org/viewvc/httpd/httpd/trunk/modules/loggers/mod_log_config.c?r1=1575394&r2=1575400&diff_format=hhttp://www-01.ibm.com/support/docview.wss?uid=swg21668973http://www-01.ibm.com/support/docview.wss?uid=swg21676091http://www-01.ibm.com/support/docview.wss?uid=swg21676092http://www.apache.org/dist/httpd/CHANGES_2.4.9http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.htmlhttp://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.htmlhttp://www.securityfocus.com/archive/1/534161/100/0/threadedhttp://www.securityfocus.com/bid/66303http://www.ubuntu.com/usn/USN-2152-1http://www.vmware.com/security/advisories/VMSA-2014-0012.htmlhttps://blogs.oracle.com/sunsecurity/entry/multiple_input_validation_vulnerabilities_in1https://httpd.apache.org/security/vulnerabilities_24.htmlhttps://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r83109088737656fa6307bd99ab40f8ff0269ae58d3f7272d7048494a%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9821b0a32a1d0a1b4947abb6f3630053fcbb2ec905d9a32c2bd4d4ee%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/ra7f6aeb28661fbf826969526585f16856abc4615877875f9d3b35ef4%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rd336919f655b7ff309385e34a143e41c503e133da80414485b3abcc9%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3Ehttps://puppet.com/security/cve/cve-2014-0098https://support.apple.com/HT204659https://support.apple.com/kb/HT6535http://advisories.mageia.org/MGASA-2014-0135.htmlhttp://archives.neohapsis.com/archives/bugtraq/2014-10/0101.htmlhttp://kb.juniper.net/InfoCenter/index?page=content&id=JSA10698http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.htmlhttp://marc.info/?l=bugtraq&m=141017844705317&w=2http://marc.info/?l=bugtraq&m=141390017113542&w=2http://seclists.org/fulldisclosure/2014/Dec/23http://secunia.com/advisories/58230http://secunia.com/advisories/58915http://secunia.com/advisories/59219http://secunia.com/advisories/59315http://secunia.com/advisories/59345http://secunia.com/advisories/60536http://security.gentoo.org/glsa/glsa-201408-12.xmlhttp://support.f5.com/kb/en-us/solutions/public/15000/300/sol15320.htmlhttp://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x/CHANGEShttp://svn.apache.org/viewvc/httpd/httpd/trunk/modules/loggers/mod_log_config.chttp://svn.apache.org/viewvc/httpd/httpd/trunk/modules/loggers/mod_log_config.c?r1=1575394&r2=1575400&diff_format=hhttp://www-01.ibm.com/support/docview.wss?uid=swg21668973http://www-01.ibm.com/support/docview.wss?uid=swg21676091http://www-01.ibm.com/support/docview.wss?uid=swg21676092http://www.apache.org/dist/httpd/CHANGES_2.4.9http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.htmlhttp://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.htmlhttp://www.securityfocus.com/archive/1/534161/100/0/threadedhttp://www.securityfocus.com/bid/66303http://www.ubuntu.com/usn/USN-2152-1http://www.vmware.com/security/advisories/VMSA-2014-0012.htmlhttps://blogs.oracle.com/sunsecurity/entry/multiple_input_validation_vulnerabilities_in1https://httpd.apache.org/security/vulnerabilities_24.htmlhttps://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r83109088737656fa6307bd99ab40f8ff0269ae58d3f7272d7048494a%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9821b0a32a1d0a1b4947abb6f3630053fcbb2ec905d9a32c2bd4d4ee%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/ra7f6aeb28661fbf826969526585f16856abc4615877875f9d3b35ef4%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E
+ 8 more references
2014-03-18
Published