First published: Sun Jul 20 2014(Updated: )
Memory leak in the winnt_accept function in server/mpm/winnt/child.c in the WinNT MPM in the Apache HTTP Server 2.4.x before 2.4.10 on Windows, when the default AcceptFilter is enabled, allows remote attackers to cause a denial of service (memory consumption) via crafted requests.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/httpd | <2.4.10 | 2.4.10 |
Apache HTTP Server | =2.4.1 | |
Apache HTTP Server | =2.4.2 | |
Apache HTTP Server | =2.4.3 | |
Apache HTTP Server | =2.4.4 | |
Apache HTTP Server | =2.4.6 | |
Apache HTTP Server | =2.4.7 | |
Apache HTTP Server | =2.4.8 | |
Apache HTTP Server | =2.4.9 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3523 has a medium severity level associated with potential denial of service due to memory consumption.
To address CVE-2014-3523, upgrade the Apache HTTP Server to version 2.4.10 or later.
CVE-2014-3523 affects Apache HTTP Server versions 2.4.1 through 2.4.9.
CVE-2014-3523 is characterized by a memory leak in the winnt_accept function, allowing attackers to exploit it for denial of service.
CVE-2014-3523 is specifically relevant to the Windows operating system when running affected versions of Apache HTTP Server.