CVE-2014-0098

Description

The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a denial of service (segmentation fault and daemon crash) via a crafted cookie that is not properly handled during truncation.

Risk Information

Base Score
7.5
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
47.397

Associated Vulnerability

VulnerabilityOS Platform
Update Apache to version 2.4.9Windows
Update Apache to version 2.2.25Windows
Multiple vulnerabilities are fixed in Apache 2.2.2Windows
Vulnerabilities CVE-2013-6438,CVE-2014-0098 are fixed in Apache 2.4.9Windows
Vulnerabilities CVE-2014-0098 are fixed in IBM WebSphere 8.5.5.3Windows
Multiple vulnerabilities are fixed in IBM WebSphere 8.0.0.9Windows
Multiple vulnerabilities are fixed in IBM WebSphere 7.0.0.33Windows
Multiple vulnerabilities are fixed in IBM WebSphere 6.1.0.47Windows
Multiple vulnerabilities are affected in Oracle HTTP Server 5.0Windows
Multiple vulnerabilities are fixed in OS X Yosemite 10.10.5 UpdateMac
Multiple vulnerabilities are fixed in OS X Yosemite 10.10.5 Combo UpdateMac
Update Apache to version 2.4.9 (For Linux)Linux
Update Apache to version 2.2.25 (For Linux)Linux
CVE-2014-0098NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-600354OS X Yosemite 10.10.5 Update
PATCH-600458OS X Yosemite 10.10.5 Combo Update

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234