The handle_headers function in mod_proxy_fcgi.c in the mod_proxy_fcgi module in the Apache HTTP Server 2.4.10 allows remote FastCGI servers to cause a denial of service (buffer over-read and daemon crash) via long response headers.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Httpd | — | Upgrade to the latest version of Apache HTTPD | Dec 15, 2014 | Dec 15, 2014 |
| Apple Osx Apache | — | Upgrade macOS to the latest versionApply OS X security update 2015-006 | Aug 28, 2015 | Dec 15, 2014 |
| Debian | — | Upgrade apache2 | Jul 30, 2024 | Dec 15, 2014 |
| Freebsd | — | Upgrade apache24 | Dec 10, 2025 | Jan 31, 2015 |
| Gentoo Linux | — | Upgrade www-servers/apache. | Oct 30, 2017 | Dec 15, 2014 |
| Oracle Solaris | — | Upgrade entire/ to version 11.4-11.4.0.0.1.15.0 on Solaris 11.4 | Oct 19, 2018 | Dec 15, 2014 |
| Suse | — | Upgrade apache2-preforkUpgrade apache2-develUpgrade apache2-example-pagesUpgrade apache2-docUpgrade apache2-workerUpgrade apache2Upgrade apache2-utilsUpgrade apache2-event | Dec 9, 2016 | Dec 15, 2014 |
| Ubuntu | — | Upgrade apache2.2-bin | Nov 8, 2024 | Dec 15, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub