CVE-2014-0098

MEDIUM

Description

The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a denial of service (segmentation fault and daemon crash) via a crafted cookie that is not properly handled during truncation.

References

http://advisories.mageia.org/MGASA-2014-0135.html

http://archives.neohapsis.com/archives/bugtraq/2014-10/0101.html

http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10698

http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.html

http://marc.info/?l=bugtraq&m=141017844705317&w=2

http://marc.info/?l=bugtraq&m=141390017113542&w=2

http://seclists.org/fulldisclosure/2014/Dec/23

http://secunia.com/advisories/58230

http://secunia.com/advisories/58915

http://secunia.com/advisories/59219

http://secunia.com/advisories/59315

http://secunia.com/advisories/59345

http://secunia.com/advisories/60536

http://security.gentoo.org/glsa/glsa-201408-12.xml

http://support.f5.com/kb/en-us/solutions/public/15000/300/sol15320.html

http://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x/CHANGES

http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/loggers/mod_log_config.c

http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/loggers/mod_log_config.c?r1=1575394&r2=1575400&diff_format=h

http://www.apache.org/dist/httpd/CHANGES_2.4.9

http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html

http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html

http://www.securityfocus.com/archive/1/534161/100/0/threaded

http://www.securityfocus.com/bid/66303

http://www.ubuntu.com/usn/USN-2152-1

http://www.vmware.com/security/advisories/VMSA-2014-0012.html

http://www-01.ibm.com/support/docview.wss?uid=swg21668973

http://www-01.ibm.com/support/docview.wss?uid=swg21676091

http://www-01.ibm.com/support/docview.wss?uid=swg21676092

https://blogs.oracle.com/sunsecurity/entry/multiple_input_validation_vulnerabilities_in1

https://httpd.apache.org/security/vulnerabilities_24.html

https://lists.apache.org/thread.html/[email protected]%3Ccvs.httpd.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Ccvs.httpd.apache.org%3E

https://puppet.com/security/cve/cve-2014-0098

https://support.apple.com/HT204659

https://support.apple.com/kb/HT6535

Details

Source: MITRE

Published: 2014-03-18

Updated: 2018-10-09

Type: CWE-20

Risk Information

CVSS v2.0

Base Score: 5

Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Impact Score: 2.9

Exploitability Score: 10

Severity: MEDIUM