Lucene search

K
cve[email protected]CVE-2014-0118
HistoryJul 20, 2014 - 11:12 a.m.

CVE-2014-0118

2014-07-2011:12:48
CWE-400
web.nvd.nist.gov
1052
2
cve-2014-0118
apache http server
mod_deflate
denial of service
resource consumption

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

6.3 Medium

AI Score

Confidence

Low

0.459 Medium

EPSS

Percentile

97.4%

The deflate_in_filter function in mod_deflate.c in the mod_deflate module in the Apache HTTP Server before 2.4.10, when request body decompression is enabled, allows remote attackers to cause a denial of service (resource consumption) via crafted request data that decompresses to a much larger size.

Affected configurations

NVD
Node
apachehttp_serverRange2.2.02.2.29
OR
apachehttp_serverRange2.4.12.4.10
Node
debiandebian_linuxMatch7.0
OR
debiandebian_linuxMatch8.0
Node
redhatjboss_enterprise_application_platformMatch6.0.0
OR
redhatjboss_enterprise_application_platformMatch6.4.0
AND
redhatenterprise_linuxMatch5.0
OR
redhatenterprise_linuxMatch6.0

References

Social References

More

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

6.3 Medium

AI Score

Confidence

Low

0.459 Medium

EPSS

Percentile

97.4%