CVE-2014-8567MOD Auth Mellon vulnerability

CWE-3997 documents7 sources
Severity
9.4CRITICALNVD
EPSS
3.8%
top 11.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 14
Latest updateMay 14

Description

The mod_auth_mellon module before 0.8.1 allows remote attackers to cause a denial of service (Apache HTTP server crash) via a crafted logout request that triggers a read of uninitialized data.

CVSS vector

AV:N/AC:L/C:N/I:C/A:CExploitability: 10.0 | Impact: 9.2

Affected Packages4 packages

Also affects: Enterprise Linux 6.6

🔴Vulnerability Details

3
GHSA
GHSA-wggx-3j62-wmwr: The mod_auth_mellon module before 02022-05-14
CVEList
CVE-2014-8567: The mod_auth_mellon module before 02014-11-14
OSV
CVE-2014-8567: The mod_auth_mellon module before 02014-11-14

📋Vendor Advisories

2
Red Hat
mod_auth_mellon: logout processing leads to denial of service2014-11-03
Debian
CVE-2014-8567: libapache2-mod-auth-mellon - The mod_auth_mellon module before 0.8.1 allows remote attackers to cause a denia...2014

💬Community

1
Bugzilla
CVE-2014-8567 mod_auth_mellon: logout processing leads to denial of service2014-10-28
CVE-2014-8567 — Uninett MOD Auth Mellon vulnerability | cvebase