CVE-2014-8566Sensitive Information Exposure in MOD Auth Mellon

Severity
6.4MEDIUMNVD
EPSS
0.9%
top 23.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 15
Latest updateMay 13

Description

The mod_auth_mellon module before 0.8.1 allows remote attackers to obtain sensitive information or cause a denial of service (segmentation fault) via unspecified vectors related to a "session overflow" involving "sessions overlapping in memory."

CVSS vector

AV:N/AC:L/C:P/I:N/A:PExploitability: 10.0 | Impact: 4.9

Affected Packages2 packages

Patches

🔴Vulnerability Details

3
GHSA
GHSA-4cw9-fccf-p75x: The mod_auth_mellon module before 02022-05-13
OSV
CVE-2014-8566: The mod_auth_mellon module before 02014-11-15
CVEList
CVE-2014-8566: The mod_auth_mellon module before 02014-11-15

📋Vendor Advisories

2
Red Hat
mod_auth_mellon: remote memory disclosure flaw2014-11-03
Debian
CVE-2014-8566: libapache2-mod-auth-mellon - The mod_auth_mellon module before 0.8.1 allows remote attackers to obtain sensit...2014

💬Community

2
Bugzilla
mod_auth_mellon: predictable session cookie in rare cases2014-10-28
Bugzilla
CVE-2014-8566 mod_auth_mellon: remote memory disclosure flaw2014-10-26