The cache_merge_headers_out function in modules/cache/cache_util.c in the mod_cache module in the Apache HTTP Server before 2.4.11 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty HTTP Content-Type header.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Httpd | — | Upgrade to the latest version of Apache HTTPD | Nov 13, 2014 | Oct 10, 2014 |
| Apple Osx Apache | — | Apply OS X security update 2015-006Upgrade macOS to the latest version | Aug 28, 2015 | Oct 10, 2014 |
| Debian | — | Upgrade apache2 | Jul 30, 2024 | Oct 10, 2014 |
| Freebsd | — | Upgrade apache24 | Dec 10, 2025 | Jan 31, 2015 |
| Gentoo Linux | — | Upgrade www-servers/apache. | Oct 30, 2017 | Oct 10, 2014 |
| Oracle Solaris | — | Upgrade entire/ to version 11.4-11.4.0.0.1.15.0 on Solaris 11.4 | Oct 19, 2018 | Oct 10, 2014 |
| Oracle_linux | — | Upgrade mod_proxy_htmlUpgrade mod_ldapUpgrade mod_sslUpgrade mod_sessionUpgrade httpdUpgrade httpd-develUpgrade httpd-manualUpgrade httpd-tools | Oct 16, 2024 | Oct 10, 2014 |
| Suse | — | Upgrade apache2-workerUpgrade apache2-docUpgrade apache2-preforkUpgrade apache2-example-pagesUpgrade apache2-develUpgrade apache2-utilsUpgrade apache2-eventUpgrade apache2 | Dec 18, 2015 | Oct 10, 2014 |
| Ubuntu | — | Upgrade apache2.2-bin | Nov 8, 2024 | Oct 10, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub