CVE-2014-8567
published 2014-11-14CVE-2014-8567: The mod_auth_mellon module before 0.8.1 allows remote attackers to cause a denial of service (Apache HTTP server crash) via a crafted logout request that…
critical9.4CVSS 3.1
AVNACLAuNCNICAC
The mod_auth_mellon module before 0.8.1 allows remote attackers to cause a denial of service (Apache HTTP server crash) via a crafted logout request that triggers a read of uninitialized data.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libapache2-mod-auth-mellon | < libapache2-mod-auth-mellon 0.9.0 (bookworm) | libapache2-mod-auth-mellon 0.9.0 (bookworm) |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| uninett | mod_auth_mellon | < 0.8.1 | 0.8.1 |
CVSS provenance
nvd9.4CRITICALAV:N/AC:L/Au:N/C:N/I:C/A:C
osv9.4CRITICAL
Red Hat
mod_auth_mellon: logout processing leads to denial of service
vendor_redhat·2014-11-03·CVSS 9.4
CVE-2014-8567 [CRITICAL] mod_auth_mellon: logout processing leads to denial of service
mod_auth_mellon: logout processing leads to denial of service
The mod_auth_mellon module before 0.8.1 allows remote attackers to cause a denial of service (Apache HTTP server crash) via a crafted logout request that triggers a read of uninitialized data.
It was found that uninitialized data could be accessed when processing a user's logout request. By attempting to log out, a user could possibly cause the Apache HTTP Server to crash.
Debian
CVE-2014-8567: libapache2-mod-auth-mellon - The mod_auth_mellon module before 0.8.1 allows remote attackers to cause a denia...
vendor_debian·2014·CVSS 9.4
CVE-2014-8567 [CRITICAL] CVE-2014-8567: libapache2-mod-auth-mellon - The mod_auth_mellon module before 0.8.1 allows remote attackers to cause a denia...
The mod_auth_mellon module before 0.8.1 allows remote attackers to cause a denial of service (Apache HTTP server crash) via a crafted logout request that triggers a read of uninitialized data.
Scope: local
bookworm: resolved (fixed in 0.9.0)
bullseye: resolved (fixed in 0.9.0)
forky: resolved (fixed in 0.9.0)
sid: resolved (fixed in 0.9.0)
trixie: resolved (fixed in 0.9.0)
GHSA
GHSA-wggx-3j62-wmwr: The mod_auth_mellon module before 0
ghsa_unreviewed·2022-05-14
CVE-2014-8567 [HIGH] GHSA-wggx-3j62-wmwr: The mod_auth_mellon module before 0
The mod_auth_mellon module before 0.8.1 allows remote attackers to cause a denial of service (Apache HTTP server crash) via a crafted logout request that triggers a read of uninitialized data.
OSV
CVE-2014-8567: The mod_auth_mellon module before 0
osv·2014-11-14·CVSS 9.4
CVE-2014-8567 [CRITICAL] CVE-2014-8567: The mod_auth_mellon module before 0
The mod_auth_mellon module before 0.8.1 allows remote attackers to cause a denial of service (Apache HTTP server crash) via a crafted logout request that triggers a read of uninitialized data.
No detection rules found.
No public exploits indexed.
http://linux.oracle.com/errata/ELSA-2014-1803.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1803.htmlhttp://secunia.com/advisories/62094http://secunia.com/advisories/62125https://github.com/UNINETT/mod_auth_mellon/commit/0f5b4fd860fa7e3a6c47201637aab05395f32647https://postlister.uninett.no/sympa/arc/modmellon/2014-11/msg00000.htmlhttp://linux.oracle.com/errata/ELSA-2014-1803.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1803.htmlhttp://secunia.com/advisories/62094http://secunia.com/advisories/62125https://github.com/UNINETT/mod_auth_mellon/commit/0f5b4fd860fa7e3a6c47201637aab05395f32647https://postlister.uninett.no/sympa/arc/modmellon/2014-11/msg00000.html
2014-11-14
Published