The lua_websocket_read function in lua_request.c in the mod_lua module in the Apache HTTP Server through 2.4.12 allows remote attackers to cause a denial of service (child-process crash) by sending a crafted WebSocket Ping frame after a Lua script has called the wsupgrade function.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Httpd | — | Upgrade to the latest version of Apache HTTPD | Jul 20, 2015 | Mar 8, 2015 |
| Apple Osx Apache | — | Upgrade macOS to the latest versionApply OS X security update 2015-006 | Aug 28, 2015 | Mar 7, 2015 |
| Debian | — | Upgrade apache2 | Jul 30, 2024 | Mar 8, 2015 |
| Freebsd | — | Upgrade apache24 | Dec 10, 2025 | Jul 15, 2015 |
| Oracle Solaris | — | Upgrade web/server/apache-22/documentation to version 2.2.31-0.175.3.1.0.3.0 on Solaris 11.3Upgrade web/server/apache-22 to version 2.2.31-0.175.3.1.0.3.0 on Solaris 11.3 | May 29, 2017 | Mar 7, 2015 |
| Suse | — | Upgrade apache2-docUpgrade apache2-example-pagesUpgrade apache2-preforkUpgrade apache2-workerUpgrade apache2-eventUpgrade apache2-develUpgrade apache2Upgrade apache2-utils | Dec 18, 2015 | Mar 7, 2015 |
| Ubuntu | — | Upgrade apache2.2-bin | Nov 8, 2024 | Mar 8, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub