CVE-2014-0117
published 2014-07-20CVE-2014-0117: The mod_proxy module in the Apache HTTP Server 2.4.x before 2.4.10, when a reverse proxy is enabled, allows remote attackers to cause a denial of service…
PriorityP432medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
35.54%
98.3th percentile
The mod_proxy module in the Apache HTTP Server 2.4.x before 2.4.10, when a reverse proxy is enabled, allows remote attackers to cause a denial of service (child-process crash) via a crafted HTTP Connection header.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apple | mac_os_x | <= 10.10.2 | — |
| apple | os_x_yosemite_v10.10.3_and_security_update_2015-004 | — | — |
| debian | apache2 | < apache2 2.4.10-1 (bookworm) | apache2 2.4.10-1 (bookworm) |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability is triggered via a crafted HTTP Connection header sent to an Apache httpd 2.4.x reverse proxy. Detection should focus on anomalous or malformed Connection header values in requests destined for reverse proxy endpoints. ↗
- →Only Apache httpd versions 2.4.6 through 2.4.9 contain the vulnerable code in mod_proxy. Scope detection/patching efforts to those specific versions. ↗
- →The flaw is in the mod_proxy module. Ensure mod_proxy is only loaded when necessary, and monitor for child-process crash events (e.g., systemd/service failure logs) on servers running httpd 2.4.6–2.4.9 with reverse proxy enabled. ↗
- ·Vulnerability only affects Apache httpd 2.4.x (specifically 2.4.6–2.4.9) with mod_proxy enabled in reverse proxy mode. httpd 2.2.x (as shipped with RHEL 5/6, JBoss products) is NOT affected. ↗
- ·The DoS impact is amplified in threaded MPM configurations. Non-threaded MPM deployments may have different crash behavior but are still considered vulnerable. ↗
- ·On Ubuntu, this issue only affected Ubuntu 14.04 LTS; other Ubuntu releases were not impacted. ↗
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2014-07-23·CVSS 4.3
CVE-2014-0117 [MEDIUM] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
Marek Kroemeke discovered that the mod_proxy module incorrectly handled
certain requests. A remote attacker could use this issue to cause the
server to stop responding, leading to a denial of service. This issue only
affected Ubuntu 14.04 LTS. (CVE-2014-0117)
Giancarlo Pellegrino and Davide Balzarotti discovered that the mod_deflate
module incorrectly handled body decompression. A remote attacker could use
this issue to cause resource consumption, leading to a denial of service.
(CVE-2014-0118)
Marek Kroemeke and others discovered that the mod_status module incorrectly
handled certain requests. A remote attacker could use this issue to cause
the server to stop responding, leadin
Red Hat
httpd: mod_proxy denial of service
vendor_redhat·2014-07-17·CVSS 4.3
CVE-2014-0117 [MEDIUM] httpd: mod_proxy denial of service
httpd: mod_proxy denial of service
The mod_proxy module in the Apache HTTP Server 2.4.x before 2.4.10, when a reverse proxy is enabled, allows remote attackers to cause a denial of service (child-process crash) via a crafted HTTP Connection header.
A denial of service flaw was found in the mod_proxy httpd module. A remote attacker could send a specially crafted request to a server configured as a reverse proxy using a threaded Multi-Processing Modules (MPM) that would cause the httpd child process to crash.
Statement: This issue did not affect the versions of httpd as shipped with Red Hat Enterprise Linux 5 and 6, Red Hat JBoss Web Server, and Red Hat JBoss Enterprise Application Platform. These products include httpd 2.2, and only httpd versions 2.4.6 through 2.4.9 include the vulnerab
Debian
CVE-2014-0117: apache2 - The mod_proxy module in the Apache HTTP Server 2.4.x before 2.4.10, when a rever...
vendor_debian·2014·CVSS 4.3
CVE-2014-0117 [MEDIUM] CVE-2014-0117: apache2 - The mod_proxy module in the Apache HTTP Server 2.4.x before 2.4.10, when a rever...
The mod_proxy module in the Apache HTTP Server 2.4.x before 2.4.10, when a reverse proxy is enabled, allows remote attackers to cause a denial of service (child-process crash) via a crafted HTTP Connection header.
Scope: local
bookworm: resolved (fixed in 2.4.10-1)
bullseye: resolved (fixed in 2.4.10-1)
forky: resolved (fixed in 2.4.10-1)
sid: resolved (fixed in 2.4.10-1)
trixie: resolved (fixed in 2.4.10-1)
Apple
CVE-2014-0117: OS X Yosemite v10.10.3 and Security Update 2015-004
vendor_apple·CVSS 4.3
CVE-2014-0117 [MEDIUM] CVE-2014-0117: OS X Yosemite v10.10.3 and Security Update 2015-004
Apple Security Update: About the security content of OS X Yosemite v10.10.3 and Security Update 2015-004
Product: OS X Yosemite v10.10.3 and Security Update 2015-004
CVE: CVE-2014-0117
Component: CVE-2014-0117
GHSA
GHSA-8qwx-34pp-wp2m: The mod_proxy module in the Apache HTTP Server 2
ghsa_unreviewed·2022-05-13
CVE-2014-0117 [MEDIUM] CWE-20 GHSA-8qwx-34pp-wp2m: The mod_proxy module in the Apache HTTP Server 2
The mod_proxy module in the Apache HTTP Server 2.4.x before 2.4.10, when a reverse proxy is enabled, allows remote attackers to cause a denial of service (child-process crash) via a crafted HTTP Connection header.
OSV
apache2 vulnerabilities
osv·2014-07-23·CVSS 4.3
CVE-2014-0117 [MEDIUM] apache2 vulnerabilities
apache2 vulnerabilities
Marek Kroemeke discovered that the mod_proxy module incorrectly handled
certain requests. A remote attacker could use this issue to cause the
server to stop responding, leading to a denial of service. This issue only
affected Ubuntu 14.04 LTS. (CVE-2014-0117)
Giancarlo Pellegrino and Davide Balzarotti discovered that the mod_deflate
module incorrectly handled body decompression. A remote attacker could use
this issue to cause resource consumption, leading to a denial of service.
(CVE-2014-0118)
Marek Kroemeke and others discovered that the mod_status module incorrectly
handled certain requests. A remote attacker could use this issue to cause
the server to stop responding, leading to a denial of service, or possibly
execute arbitrary code. (CVE-2014-0226)
Rainer
OSV
CVE-2014-0117: The mod_proxy module in the Apache HTTP Server 2
osv·2014-07-20·CVSS 4.3
CVE-2014-0117 [MEDIUM] CVE-2014-0117: The mod_proxy module in the Apache HTTP Server 2
The mod_proxy module in the Apache HTTP Server 2.4.x before 2.4.10, when a reverse proxy is enabled, allows remote attackers to cause a denial of service (child-process crash) via a crafted HTTP Connection header.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0117 httpd: mod_proxy denial of service
bugzilla·2014-07-17·CVSS 4.3
CVE-2014-0117 [MEDIUM] CVE-2014-0117 httpd: mod_proxy denial of service
CVE-2014-0117 httpd: mod_proxy denial of service
The following flaw has been fixed in the Apache HTTP Server:
"A flaw was found in mod_proxy. A remote attacker could send a carefully crafted request to a server configured as a reverse proxy, and cause the child process to crash. This could lead to a denial of service against a threaded MPM."
External References:
http://httpd.apache.org/security/vulnerabilities_24.html
Discussion:
Created httpd tracking bugs for this issue:
Affects: fedora-all [bug 1120614]
---
Statement:
This issue did not affect the versions of httpd as shipped with Red Hat Enterprise Linux 5 and 6, Red Hat JBoss Web Server, and Red Hat JBoss Enterprise Application Platform. These products include httpd 2.2, and only httpd versions 2.4.6 through 2.4.9 include th
Bugzilla
CVE-2014-0231 CVE-2014-0118 CVE-2014-0117 CVE-2014-0226 CVE-2013-4352 httpd: various flaws [fedora-all]
bugzilla·2014-07-17·CVSS 4.3
CVE-2014-0231 [MEDIUM] CVE-2014-0231 CVE-2014-0118 CVE-2014-0117 CVE-2014-0226 CVE-2013-4352 httpd: various flaws [fedora-all]
CVE-2014-0231 CVE-2014-0118 CVE-2014-0117 CVE-2014-0226 CVE-2013-4352 httpd: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: th
http://advisories.mageia.org/MGASA-2014-0305.htmlhttp://httpd.apache.org/security/vulnerabilities_24.htmlhttp://lists.apple.com/archives/security-announce/2015/Apr/msg00001.htmlhttp://seclists.org/fulldisclosure/2014/Jul/117http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/proxy/mod_proxy_http.chttp://svn.apache.org/viewvc/httpd/httpd/trunk/modules/proxy/mod_proxy_http.c?r1=1599486&r2=1610674&diff_format=hhttp://svn.apache.org/viewvc/httpd/httpd/trunk/modules/proxy/proxy_util.chttp://svn.apache.org/viewvc/httpd/httpd/trunk/modules/proxy/proxy_util.c?r1=1609680&r2=1610674&diff_format=hhttp://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.htmlhttp://zerodayinitiative.com/advisories/ZDI-14-239/https://bugzilla.redhat.com/show_bug.cgi?id=1120599https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37ea993dfce68d1d%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r83109088737656fa6307bd99ab40f8ff0269ae58d3f7272d7048494a%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9821b0a32a1d0a1b4947abb6f3630053fcbb2ec905d9a32c2bd4d4ee%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/ra7f6aeb28661fbf826969526585f16856abc4615877875f9d3b35ef4%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://support.apple.com/HT204659http://advisories.mageia.org/MGASA-2014-0305.htmlhttp://httpd.apache.org/security/vulnerabilities_24.htmlhttp://lists.apple.com/archives/security-announce/2015/Apr/msg00001.htmlhttp://seclists.org/fulldisclosure/2014/Jul/117http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/proxy/mod_proxy_http.chttp://svn.apache.org/viewvc/httpd/httpd/trunk/modules/proxy/mod_proxy_http.c?r1=1599486&r2=1610674&diff_format=hhttp://svn.apache.org/viewvc/httpd/httpd/trunk/modules/proxy/proxy_util.chttp://svn.apache.org/viewvc/httpd/httpd/trunk/modules/proxy/proxy_util.c?r1=1609680&r2=1610674&diff_format=hhttp://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.htmlhttp://zerodayinitiative.com/advisories/ZDI-14-239/https://bugzilla.redhat.com/show_bug.cgi?id=1120599https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37ea993dfce68d1d%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r83109088737656fa6307bd99ab40f8ff0269ae58d3f7272d7048494a%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9821b0a32a1d0a1b4947abb6f3630053fcbb2ec905d9a32c2bd4d4ee%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/ra7f6aeb28661fbf826969526585f16856abc4615877875f9d3b35ef4%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://support.apple.com/HT204659
2014-07-20
Published