CVE-2014-3523

Description

Memory leak in the winnt_accept function in server/mpm/winnt/child.c in the WinNT MPM in the Apache HTTP Server 2.4.x before 2.4.10 on Windows, when the default AcceptFilter is enabled, allows remote attackers to cause a denial of service (memory consumption) via crafted requests.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
35.235

Associated Vulnerability

VulnerabilityOS Platform
Update Apache to version 2.4.10Windows
Vulnerabilities CVE-2014-3523 are fixed in Apache 2.4.10Windows
Multiple vulnerabilities are fixed in IBM WebSphere 8.5.5.4Windows
Multiple vulnerabilities are fixed in IBM WebSphere 8.0.0.10Windows
Multiple vulnerabilities are fixed in IBM WebSphere 7.0.0.35Windows
Update Apache to version 2.4.10 (For Linux)Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234