CVE-2014-8567 — MOD Auth Mellon vulnerability
Severity
9.4CRITICALNVD
EPSS
3.8%
top 11.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 14
Latest updateMay 14
Description
The mod_auth_mellon module before 0.8.1 allows remote attackers to cause a denial of service (Apache HTTP server crash) via a crafted logout request that triggers a read of uninitialized data.
CVSS vector
AV:N/AC:L/C:N/I:C/A:CExploitability: 10.0 | Impact: 9.2
Affected Packages4 packages
Also affects: Enterprise Linux 6.6