First published: Mon Oct 06 2014(Updated: )
It was reported that if Content-Type header value is empty, httpd with mod_cache enabled will segfault: <a href="https://issues.apache.org/bugzilla/show_bug.cgi?id=56924">https://issues.apache.org/bugzilla/show_bug.cgi?id=56924</a> Upstream patch: <a href="http://svn.apache.org/viewvc?view=revision&revision=1624234">http://svn.apache.org/viewvc?view=revision&revision=1624234</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/httpd | <2.4.11 | 2.4.11 |
Apache HTTP Server | =2.4.1 | |
Apache HTTP Server | =2.4.2 | |
Apache HTTP Server | =2.4.3 | |
Apache HTTP Server | =2.4.4 | |
Apache HTTP Server | =2.4.6 | |
Apache HTTP Server | =2.4.7 | |
Apache HTTP Server | =2.4.9 | |
Apache HTTP Server | =2.4.10 | |
Ubuntu | =10.04 | |
Ubuntu | =12.04 | |
Ubuntu | =14.04 | |
Ubuntu | =14.10 | |
Red Hat Enterprise Linux Desktop | =7.0 | |
Red Hat Enterprise Linux Server EUS | =7.3 | |
Red Hat Enterprise Linux Server EUS | =7.4 | |
Red Hat Enterprise Linux Server EUS | =7.5 | |
Red Hat Enterprise Linux Server EUS | =7.6 | |
Red Hat Enterprise Linux Server EUS | =7.7 | |
Red Hat Enterprise Linux Server | =7.0 | |
Red Hat Enterprise Linux Server | =7.3 | |
Red Hat Enterprise Linux Server | =7.4 | |
Red Hat Enterprise Linux Server | =7.6 | |
Red Hat Enterprise Linux Server | =7.7 | |
Red Hat Enterprise Linux Server | =7.3 | |
Red Hat Enterprise Linux Server | =7.6 | |
Red Hat Enterprise Linux Server | =7.7 | |
Oracle Enterprise Manager Ops Center | <12.1.4 | |
Oracle Enterprise Manager Ops Center | =12.2.0 | |
Oracle Enterprise Manager Ops Center | =12.2.1 | |
Oracle Enterprise Manager Ops Center | =12.3.0 | |
Oracle Linux | =6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3581 is classified as a critical severity vulnerability.
To fix CVE-2014-3581, upgrade to Apache HTTP Server version 2.4.11 or later.
CVE-2014-3581 affects Apache HTTP Server versions from 2.4.1 to 2.4.10.
Exploitation of CVE-2014-3581 can lead to a segmentation fault and denial of service.
Yes, CVE-2014-3581 is specifically related to the mod_cache feature in Apache HTTP Server.