CVE-2014-0117

Description

The mod_proxy module in the Apache HTTP Server 2.4.x before 2.4.10, when a reverse proxy is enabled, allows remote attackers to cause a denial of service (child-process crash) via a crafted HTTP Connection header.

Risk Information

Base Score
7.5
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
56.996

Associated Vulnerability

VulnerabilityOS Platform
Update Apache to version 2.4.10Windows
Vulnerabilities CVE-2014-0117 are fixed in Apache 2.4.10Windows
Multiple vulnerabilities are fixed in IBM WebSphere 8.5.5.4Windows
Multiple vulnerabilities are fixed in IBM WebSphere 8.0.0.10Windows
Multiple vulnerabilities are fixed in IBM WebSphere 7.0.0.35Windows
Httpd24-httpd update (ELSA-2014-1972) httpd24-httpd-2.4.6-22.0.1.el6.x86_64.rpmLinux
Httpd24-httpd-devel update (ELSA-2014-1972) httpd24-httpd-devel-2.4.6-22.0.1.el6.x86_64.rpmLinux
Httpd24-httpd-tools update (ELSA-2014-1972) httpd24-httpd-tools-2.4.6-22.0.1.el6.x86_64.rpmLinux
Httpd24-mod_ldap update (ELSA-2014-1972) httpd24-mod_ldap-2.4.6-22.0.1.el6.x86_64.rpmLinux
Httpd24-mod_proxy_html update (ELSA-2014-1972) httpd24-mod_proxy_html-2.4.6-22.0.1.el6.x86_64.rpmLinux
Httpd24-mod_session update (ELSA-2014-1972) httpd24-mod_session-2.4.6-22.0.1.el6.x86_64.rpmLinux
Httpd24-mod_ssl update (ELSA-2014-1972) httpd24-mod_ssl-2.4.6-22.0.1.el6.x86_64.rpmLinux
Httpd24-httpd-manual update (ELSA-2014-1972) httpd24-httpd-manual-2.4.6-22.0.1.el6.noarch.rpmLinux
Update Apache to version 2.4.10 (For Linux)Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234