CVE-2014-3581
Publication date 10 October 2014
Last updated 24 July 2024
Ubuntu priority
The cache_merge_headers_out function in modules/cache/cache_util.c in the mod_cache module in the Apache HTTP Server before 2.4.11 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty HTTP Content-Type header.
Status
Package | Ubuntu Release | Status |
---|---|---|
apache2 | ||
14.04 LTS trusty |
Fixed 2.4.7-1ubuntu4.4
|
|
Notes
Patch details
Package | Patch details |
---|---|
apache2 |
|
References
Related Ubuntu Security Notices (USN)
- USN-2523-1
- Apache HTTP Server vulnerabilities
- 10 March 2015