Описание
Multiple serious vulnerabilities have been found in Apache HTTP Server. Malicious users can exploit these vulnerabilities to cause a denial of service.
Below is a complete list of vulnerabilities
- Stack recursion crash in the mod_lua module in the lua_request.c file in lua_websocket_read function can lead to cause a denial of service via specially crafted PING request.
- The read_request_line function in server/protocol.c file doesn’t properly initialize the protocol structure member which can lead to cause a denial of service via specially crafted request.
- The chunked transfer coding implementation parse chunk headers improperly which can lead to HTTP Request Smuggling Attack via a specially crafted request
- The ap_some_auth_required function in server/request.c file has design error which renders the API unusuable.
Первичный источник обнаружения
Связанные продукты
Список CVE
- CVE-2015-0228 critical
- CVE-2015-0253 critical
- CVE-2015-3183 critical
- CVE-2015-3185 warning
Смотрите также
Узнай статистику распространения уязвимостей в своем регионе statistics.securelist.com
Нашли неточность в описании этой уязвимости? Дайте нам знать!