CVE-2014-3581

Apache HTTP Server - Denial of Service via Empty Content-Type Header

Title source: llm
STIX 2.1

Description

The cache_merge_headers_out function in modules/cache/cache_util.c in the mod_cache module in the Apache HTTP Server before 2.4.11 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty HTTP Content-Type header.

References (29)

Core 29
Core References
Patch, Vendor Advisory x_refsource_confirm
http://svn.apache.org/viewvc?view=revision&revision=1624234
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0325.html
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2523-1
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1031005
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/97027
Broken Link, Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html
Issue Tracking, Patch, Third Party Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1149709
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/71656
Broken Link, Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2015/Sep/msg00004.html
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201610-02
Third Party Advisory x_refsource_confirm
https://support.apple.com/kb/HT205031
Third Party Advisory x_refsource_confirm
https://support.apple.com/HT205219

Scores

EPSS 0.0481
EPSS Percentile 89.6%

Details

CWE
CWE-476
Status published
Products (31)
apache/http_server 2.4.1
apache/http_server 2.4.2
apache/http_server 2.4.3
apache/http_server 2.4.4
apache/http_server 2.4.6
apache/http_server 2.4.7
apache/http_server 2.4.9
apache/http_server 2.4.10
canonical/ubuntu_linux 10.04
canonical/ubuntu_linux 12.04
... and 21 more
Published Oct 10, 2014
Tracked Since Feb 18, 2026