Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2014-0226Race Condition in Apache Http Server

Severity
6.8MEDIUMNVD
EPSS
75.4%
top 1.11%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJul 20
Latest updateMay 13

Description

Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service (heap-based buffer overflow), or possibly obtain sensitive credential information or execute arbitrary code, via a crafted request that triggers improper scoreboard handling within the status_handler function in modules/generators/mod_status.c and the lua_ap_scoreboard_worker function in modules/lua/lua_request.c.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages5 packages

NVDapache/http_server2.2.02.2.29+1
NVDoracle/http_server4 versions+3

Also affects: Debian Linux 7.0, 8.0

Patches

🔴Vulnerability Details

4
GHSA
GHSA-9c3m-phm4-whxx: Race condition in the mod_status module in the Apache HTTP Server before 22022-05-13
OSV
apache2 vulnerabilities2014-07-23
OSV
CVE-2014-0226: Race condition in the mod_status module in the Apache HTTP Server before 22014-07-20
CVEList
CVE-2014-0226: Race condition in the mod_status module in the Apache HTTP Server before 22014-07-20

💥Exploits & PoCs

1
Exploit-DB
Apache 2.4.7 mod_status - Scoreboard Handling Race Condition2014-07-21

📋Vendor Advisories

4
Ubuntu
Apache HTTP Server vulnerabilities2014-07-23
Red Hat
httpd: mod_status heap-based buffer overflow2014-07-17
Debian
CVE-2014-0226: apache2 - Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 ...2014
Apple
CVE-2014-0226: OS X Yosemite v10.10.3 and Security Update 2015-004

💬Community

2
Bugzilla
CVE-2014-0231 CVE-2014-0118 CVE-2014-0117 CVE-2014-0226 CVE-2013-4352 httpd: various flaws [fedora-all]2014-07-17
Bugzilla
CVE-2014-0226 httpd: mod_status heap-based buffer overflow2014-07-17
CVE-2014-0226 — Race Condition in Apache Http Server | cvebase