Vulnerability Database

296,138

Total vulnerabilities in the database

CVE-2014-3583

The handle_headers function in mod_proxy_fcgi.c in the mod_proxy_fcgi module in the Apache HTTP Server 2.4.10 allows remote FastCGI servers to cause a denial of service (buffer over-read and daemon crash) via long response headers.

  • Published: Dec 15, 2014
  • Updated: Apr 13, 2023
  • CVE: CVE-2014-3583
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 5
  • AV:N/AC:L/Au:N/C:N/I:N/A:P

CWEs:

Software From Fixed in
apple / mac_os_x 10.10.0 10.10.0.x
apple / mac_os_x 10.10.4 10.10.4.x
apple / mac_os_x 10.10.1 10.10.1.x
apple / mac_os_x 10.9.5 10.9.5.x
apple / mac_os_x 10.10.3 10.10.3.x
apple / mac_os_x 10.10.2 10.10.2.x
apple / os_x_server 5.0.3 5.0.3.x
apache / http_server 2.4.10 2.4.10.x
canonical / ubuntu_linux 12.04 12.04.x
canonical / ubuntu_linux 14.10 14.10.x
canonical / ubuntu_linux 14.04 14.04.x
canonical / ubuntu_linux 10.04 10.04.x