Vulnerability Description
The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a denial of service (segmentation fault and daemon crash) via a crafted cookie that is not properly handled during truncation.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Http Server | >= 2.2.0, < 2.2.27 |
| Oracle | Http Server | 10.1.3.5.0 |
| Oracle | Secure Global Desktop | 4.63 |
| Canonical | Ubuntu Linux | 10.04 |
References
- http://advisories.mageia.org/MGASA-2014-0135.htmlThird Party Advisory
- http://archives.neohapsis.com/archives/bugtraq/2014-10/0101.htmlBroken Link
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10698Third Party Advisory
- http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.htmlBroken LinkMailing List
- http://marc.info/?l=bugtraq&m=141017844705317&w=2Issue TrackingMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=141390017113542&w=2Issue TrackingMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2014/Dec/23Mailing ListThird Party Advisory
- http://secunia.com/advisories/58230Not Applicable
- http://secunia.com/advisories/58915Not Applicable
- http://secunia.com/advisories/59219Not Applicable
- http://secunia.com/advisories/59315Not Applicable
- http://secunia.com/advisories/59345Not Applicable
- http://secunia.com/advisories/60536Not Applicable
- http://security.gentoo.org/glsa/glsa-201408-12.xmlThird Party Advisory
- http://support.f5.com/kb/en-us/solutions/public/15000/300/sol15320.htmlThird Party Advisory
FAQ
What is CVE-2014-0098?
CVE-2014-0098 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a denial of service (segmentation fault and daemon cras...
How severe is CVE-2014-0098?
CVE-2014-0098 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-0098?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Http Server, Oracle Http Server, Oracle Secure Global Desktop, Canonical Ubuntu Linux.