CVE ID | CVE-2014-0226 |
CVSS SCORE | 7.5, AV:N/AC:L/Au:N/C:P/I:P/A:P |
AFFECTED VENDORS |
Apache |
AFFECTED PRODUCTS |
HTTPD Server 2.x |
VULNERABILITY DETAILS |
The specific flaw exists within the updating of mod_status. A race condition in mod_status allows an attacker to disclose information or corrupt memory with several requests to endpoints with handler server-status and other endpoints. By abusing this flaw, an attacker can possibly disclose credentials or leverage this situation to achieve remote code execution. |
ADDITIONAL DETAILS |
Apache has issued an update to correct this vulnerability. More details can be found at:
http://mail-archives.apache.org/mod_mbox/httpd-cvs/201407.mbox/%3C20140714195504.EF60D23889E2@eris.apache.org%3E |
DISCLOSURE TIMELINE |
|
CREDIT | AKAT-1 22733db72ab3ed94b5f8a1ffcde850251fe6f466 Marek Kroemeke |