CVE-2014-2668: Input Validation
Published Mar 28, 2014
·Updated
Apache CouchDB 1.5.0 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via the count parameter to /uuids.
Affected Software
1 affected component
Apache CouchDB<=1.5.0
Event History
Mar 28, 2014
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:51 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-2668?
CVE-2014-2668 is classified as a moderate severity vulnerability due to its potential for denial of service.
2
How do I fix CVE-2014-2668?
To fix CVE-2014-2668, upgrade Apache CouchDB to version 1.6.0 or later.
3
What type of attack does CVE-2014-2668 enable?
CVE-2014-2668 enables remote attackers to perform a denial of service attack through CPU and memory exhaustion.
4
Which versions of Apache CouchDB are affected by CVE-2014-2668?
Apache CouchDB versions 1.5.0 and earlier are affected by CVE-2014-2668.
5
What is the impact of CVE-2014-2668?
The impact of CVE-2014-2668 is increased consumption of CPU and memory resources, potentially leading to service unavailability.