CVE-2014-3523

Apache HTTP Server < 2.4.10 - Memory Leak in WinNT MPM AcceptFilter

Title source: llm
STIX 2.1

Description

Memory leak in the winnt_accept function in server/mpm/winnt/child.c in the WinNT MPM in the Apache HTTP Server 2.4.x before 2.4.10 on Windows, when the default AcceptFilter is enabled, allows remote attackers to cause a denial of service (memory consumption) via crafted requests.

References (21)

Core 21
Core References
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=144050155601375&w=2
Patch, Vendor Advisory x_refsource_confirm
http://httpd.apache.org/security/vulnerabilities_24.html
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=143748090628601&w=2
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2016-2957.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/68747

Scores

EPSS 0.3523
EPSS Percentile 97.1%

Details

CWE
CWE-399
Status published
Products (8)
apache/http_server 2.4.1
apache/http_server 2.4.2
apache/http_server 2.4.3
apache/http_server 2.4.4
apache/http_server 2.4.6
apache/http_server 2.4.7
apache/http_server 2.4.8
apache/http_server 2.4.9
Published Jul 20, 2014
Tracked Since Feb 18, 2026