CVE-2013-4352

Apache HTTP Server 2.4.6 - Denial of Service via Missing Hostname in mod_cache

Title source: llm
STIX 2.1

Description

The cache_invalidate function in modules/cache/cache_storage.c in the mod_cache module in the Apache HTTP Server 2.4.6, when a caching forward proxy is enabled, allows remote HTTP servers to cause a denial of service (NULL pointer dereference and daemon crash) via vectors that trigger a missing hostname value.

References (16)

Core 16
Core References
Vendor Advisory x_refsource_confirm
http://httpd.apache.org/security/vulnerabilities_24.html
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1120604

Scores

EPSS 0.2435
EPSS Percentile 96.2%

Details

Status published
Products (1)
apache/http_server 2.4.6
Published Jul 20, 2014
Tracked Since Feb 18, 2026