CVE-2014-0118 — Uncontrolled Resource Consumption in Apache Http Server
Severity
4.3MEDIUMNVD
EPSS
41.3%
top 2.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 20
Latest updateMay 13
Description
The deflate_in_filter function in mod_deflate.c in the mod_deflate module in the Apache HTTP Server before 2.4.10, when request body decompression is enabled, allows remote attackers to cause a denial of service (resource consumption) via crafted request data that decompresses to a much larger size.
CVSS vector
AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9
Affected Packages2 packages
Also affects: Debian Linux 7.0, 8.0
Patches
🔴Vulnerability Details
4📋Vendor Advisories
4Debian▶
CVE-2014-0118: apache2 - The deflate_in_filter function in mod_deflate.c in the mod_deflate module in the...↗2014