CWE
20
Advisory Published
CVE Published
Updated

CVE-2014-0117: Input Validation

First published: Thu Jul 17 2014(Updated: )

The following flaw has been fixed in the Apache HTTP Server: "A flaw was found in mod_proxy. A remote attacker could send a carefully crafted request to a server configured as a reverse proxy, and cause the child process to crash. This could lead to a denial of service against a threaded MPM." External References: <a href="http://httpd.apache.org/security/vulnerabilities_24.html">http://httpd.apache.org/security/vulnerabilities_24.html</a>

Credit: secalert@redhat.com

Affected SoftwareAffected VersionHow to fix
redhat/httpd<2.4.10
2.4.10
Apache Http Server=2.4.6
Apache Http Server=2.4.7
Apache Http Server=2.4.8
Apache Http Server=2.4.9
Apple iOS and macOS<=10.10.2

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Reference Links

Frequently Asked Questions

  • What is the severity of CVE-2014-0117?

    CVE-2014-0117 has been classified as a high-severity vulnerability due to its potential to cause denial of service.

  • How does CVE-2014-0117 affect Apache HTTP Server?

    CVE-2014-0117 allows a remote attacker to send a crafted request to a reverse proxy, leading to a crash of the child process.

  • How do I fix CVE-2014-0117?

    To fix CVE-2014-0117, upgrade your Apache HTTP Server to version 2.4.10 or later.

  • Which versions of Apache HTTP Server are affected by CVE-2014-0117?

    CVE-2014-0117 affects Apache HTTP Server versions 2.4.6 through 2.4.9.

  • Is macOS Yosemite affected by CVE-2014-0117?

    Yes, macOS Yosemite is affected if it is running an older version of Apache HTTP Server up to 10.10.2.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203