CVE-2014-0118Uncontrolled Resource Consumption in Apache Http Server

Severity
4.3MEDIUMNVD
EPSS
41.3%
top 2.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 20
Latest updateMay 13

Description

The deflate_in_filter function in mod_deflate.c in the mod_deflate module in the Apache HTTP Server before 2.4.10, when request body decompression is enabled, allows remote attackers to cause a denial of service (resource consumption) via crafted request data that decompresses to a much larger size.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

NVDapache/http_server2.2.02.2.29+1

Also affects: Debian Linux 7.0, 8.0

Patches

🔴Vulnerability Details

4
GHSA
GHSA-m8vg-h7wr-m54w: The deflate_in_filter function in mod_deflate2022-05-13
OSV
apache2 vulnerabilities2014-07-23
CVEList
CVE-2014-0118: The deflate_in_filter function in mod_deflate2014-07-20
OSV
CVE-2014-0118: The deflate_in_filter function in mod_deflate2014-07-20

📋Vendor Advisories

4
Ubuntu
Apache HTTP Server vulnerabilities2014-07-23
Red Hat
httpd: mod_deflate denial of service2014-07-17
Debian
CVE-2014-0118: apache2 - The deflate_in_filter function in mod_deflate.c in the mod_deflate module in the...2014
Apple
CVE-2014-0118: OS X Yosemite v10.10.3 and Security Update 2015-004

💬Community

2
Bugzilla
CVE-2014-0231 CVE-2014-0118 CVE-2014-0117 CVE-2014-0226 CVE-2013-4352 httpd: various flaws [fedora-all]2014-07-17
Bugzilla
CVE-2014-0118 httpd: mod_deflate denial of service2014-07-17
CVE-2014-0118 — Uncontrolled Resource Consumption | cvebase