CVE-2014-0226: Buffer Overflow
Race condition in the modstatus module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service (heap-based buffer overflow), or possibly obtain sensitive credential information or execute arbitrary code, via a crafted request that triggers improper scoreboard handling within the statushandler function in modules/generators/modstatus.c and the luaapscoreboardworker function in modules/lua/luarequest.c.
Other sources
The following flaw has been fixed in the Apache HTTP Server:
"A race condition was found in modstatus. An attacker able to access a public server status page on a server using a threaded MPM could send a carefully crafted request which could lead to a heap buffer overflow. Note that it is not a default or recommended configuration to have a public accessible server status page."
External References:
http://httpd.apache.org/security/vulnerabilities24.html
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0226?
CVE-2014-0226 is considered a high-severity vulnerability that can lead to denial of service and potential remote code execution.
How do I fix CVE-2014-0226?
To fix CVE-2014-0226, upgrade your Apache HTTP Server to version 2.4.10 or later.
What systems are affected by CVE-2014-0226?
CVE-2014-0226 affects Apache HTTP Server versions prior to 2.4.10 and versions 2.2.0 to 2.2.29.
Can CVE-2014-0226 lead to data exposure?
Yes, CVE-2014-0226 may allow remote attackers to obtain sensitive credential information.
Is CVE-2014-0226 a known vulnerability in enterprise environments?
Yes, CVE-2014-0226 has been recognized as a significant risk in enterprise environments using vulnerable versions of Apache HTTP Server.