The cache_invalidate function in modules/cache/cache_storage.c in the mod_cache module in the Apache HTTP Server 2.4.6, when a caching forward proxy is enabled, allows remote HTTP servers to cause a denial of service (NULL pointer dereference and daemon crash) via vectors that trigger a missing hostname value.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Httpd | — | Upgrade to the latest version of Apache HTTPD | Jul 20, 2014 | Jul 20, 2014 |
| Centos_linux | — | Upgrade httpd-develUpgrade httpdUpgrade httpd-manualUpgrade httpd-toolsUpgrade mod_sslUpgrade mod_sessionUpgrade mod_ldapUpgrade mod_proxy_html | Dec 1, 2016 | Jul 20, 2014 |
| Debian | — | Upgrade apache2 | Jul 30, 2024 | Jul 20, 2014 |
| Oracle Solaris | — | Upgrade web/server/apache-22 to version 2.2.27-0.175.2.2.0.3.0 on Solaris 11.2 | May 29, 2017 | Jul 20, 2014 |
| Oracle_linux | — | Upgrade httpd-toolsUpgrade httpd-manualUpgrade httpd-develUpgrade httpdUpgrade mod_ldapUpgrade mod_sslUpgrade mod_proxy_htmlUpgrade mod_session | Oct 16, 2024 | Jul 20, 2014 |
| Suse | — | Upgrade apache2-preforkUpgrade apache2-workerUpgrade apache2-develUpgrade apache2Upgrade apache2-example-pagesUpgrade apache2-eventUpgrade apache2-docUpgrade apache2-utils | Sep 30, 2014 | Jul 20, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub