advisories.mageia.orgConfirmation
http://advisories.mageia.org/MGASA-2014-0304.html CVE-2014-0226
Apache 2.4.7 mod_status - Scoreboard Handling Race Condition
Record summary
CVE-2014-0226 has a selected CVSS score of 6.8; EIP currently links 1 catalogued exploit and 1 repository PoC.
Description
Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service (heap-based buffer overflow), or possibly obtain sensitive credential information or execute arbitrary code, via a crafted request that triggers improper scoreboard handling within the status_handler function in modules/generators/mod_status.c and the lua_ap_scoreboard_worker function in modules/lua/lua_request.c.
Description source: CVE List
Exploitation context
Proofs of concept
2Catalogued exploits
ExploitDBApache 2.4.7 mod_status - Scoreboard Handling Race ConditionExploitDB exploitby Marek KroemekeNot analyzed1 file
Repository PoCs
GitHubshreesh1/CVE-2014-0226-pocRepository PoCby shreesh1Stars: 0Not analyzed2 files
References
Showing 12 of 75advisories.mageia.orgConfirmation
http://advisories.mageia.org/MGASA-2014-0305.html httpd.apache.orgConfirmation
http://httpd.apache.org/security/vulnerabilities_24.html APPLE-SA-2015-04-08-2Vendor advisory
http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.html SSRT102066Vendor advisory
http://marc.info/?l=bugtraq&m=143403519711434&w=2 HPSBMU03380Vendor advisory
http://marc.info/?l=bugtraq&m=143748090628601&w=2 HPSBMU03409Vendor advisory
http://marc.info/?l=bugtraq&m=144050155601375&w=2 HPSBUX03512Vendor advisory
http://marc.info/?l=bugtraq&m=144493176821532&w=2 RHSA-2014:1019Vendor advisory
http://rhn.redhat.com/errata/RHSA-2014-1019.html RHSA-2014:1020Vendor advisory
http://rhn.redhat.com/errata/RHSA-2014-1020.html RHSA-2014:1021Vendor advisory
http://rhn.redhat.com/errata/RHSA-2014-1021.html 20140721 Apache HTTPd - description of the CVE-2014-0226.mailing list
http://seclists.org/fulldisclosure/2014/Jul/114