The mod_auth_mellon module before 0.8.1 allows remote attackers to cause a denial of service (Apache HTTP server crash) via a crafted logout request that triggers a read of uninitialized data.
CVSS Details
- CVSS 3.1 Base Score: 9.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade mod_auth_mellon | Dec 1, 2016 | Nov 14, 2014 |
| Debian | — | Upgrade libapache2-mod-auth-mellon | Jul 30, 2024 | Nov 14, 2014 |
| Oracle_linux | — | Upgrade mod_auth_mellon | Oct 16, 2024 | Nov 14, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub