CVE-2013-4352

Description

The cache_invalidate function in modules/cache/cache_storage.c in the mod_cache module in the Apache HTTP Server 2.4.6, when a caching forward proxy is enabled, allows remote HTTP servers to cause a denial of service (NULL pointer dereference and daemon crash) via vectors that trigger a missing hostname value.

Risk Information

Base Score
7.5
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
24.352

Associated Vulnerability

VulnerabilityOS Platform
Update Apache to version 2.4.7Windows
Multiple vulnerabilities are fixed in IBM WebSphere 8.5.5.4Windows
Multiple vulnerabilities are fixed in IBM WebSphere 8.0.0.10Windows
Multiple vulnerabilities are fixed in IBM WebSphere 7.0.0.35Windows
Httpd24-httpd update (ELSA-2014-1972) httpd24-httpd-2.4.6-22.0.1.el6.x86_64.rpmLinux
Httpd24-httpd-devel update (ELSA-2014-1972) httpd24-httpd-devel-2.4.6-22.0.1.el6.x86_64.rpmLinux
Httpd24-httpd-tools update (ELSA-2014-1972) httpd24-httpd-tools-2.4.6-22.0.1.el6.x86_64.rpmLinux
Httpd24-mod_ldap update (ELSA-2014-1972) httpd24-mod_ldap-2.4.6-22.0.1.el6.x86_64.rpmLinux
Httpd24-mod_proxy_html update (ELSA-2014-1972) httpd24-mod_proxy_html-2.4.6-22.0.1.el6.x86_64.rpmLinux
Httpd24-mod_session update (ELSA-2014-1972) httpd24-mod_session-2.4.6-22.0.1.el6.x86_64.rpmLinux
Httpd24-mod_ssl update (ELSA-2014-1972) httpd24-mod_ssl-2.4.6-22.0.1.el6.x86_64.rpmLinux
Httpd24-httpd-manual update (ELSA-2014-1972) httpd24-httpd-manual-2.4.6-22.0.1.el6.noarch.rpmLinux
Update Apache to version 2.4.7 (For Linux)Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234