CVE-2014-0117Improper Input Validation in Apache Http Server

Severity
4.3MEDIUMNVD
EPSS
57.0%
top 1.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 20
Latest updateMay 13

Description

The mod_proxy module in the Apache HTTP Server 2.4.x before 2.4.10, when a reverse proxy is enabled, allows remote attackers to cause a denial of service (child-process crash) via a crafted HTTP Connection header.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

NVDapache/http_server4 versions+3
NVDapple/mac_os_x10.10.2

Patches

🔴Vulnerability Details

4
GHSA
GHSA-8qwx-34pp-wp2m: The mod_proxy module in the Apache HTTP Server 22022-05-13
OSV
apache2 vulnerabilities2014-07-23
OSV
CVE-2014-0117: The mod_proxy module in the Apache HTTP Server 22014-07-20
CVEList
CVE-2014-0117: The mod_proxy module in the Apache HTTP Server 22014-07-20

📋Vendor Advisories

4
Ubuntu
Apache HTTP Server vulnerabilities2014-07-23
Red Hat
httpd: mod_proxy denial of service2014-07-17
Debian
CVE-2014-0117: apache2 - The mod_proxy module in the Apache HTTP Server 2.4.x before 2.4.10, when a rever...2014
Apple
CVE-2014-0117: OS X Yosemite v10.10.3 and Security Update 2015-004

💬Community

2
Bugzilla
CVE-2014-0117 httpd: mod_proxy denial of service2014-07-17
Bugzilla
CVE-2014-0231 CVE-2014-0118 CVE-2014-0117 CVE-2014-0226 CVE-2013-4352 httpd: various flaws [fedora-all]2014-07-17
CVE-2014-0117 — Improper Input Validation in Apache | cvebase