CVE-2014-0098
Last modified
CVE-2014-0098 is a vulnerability of currently unknown severity. The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a denial of service (segmentation fault and daemon crash) via a crafted cookie that is not properly handled during truncation.. EPSS estimates a 26.00% chance of exploitation in the next 30 days.
Description
The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a denial of service (segmentation fault and daemon crash) via a crafted cookie that is not properly handled during truncation.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Http Server | >= 2.2.0, < 2.2.27 |
| Apache | Http Server | >= 2.4.1, < 2.4.9 |
| Oracle | Http Server | 10.1.3.5.0 |
| Oracle | Http Server | 11.1.1.7.0 |
| Oracle | Http Server | 12.1.2.0 |
| Oracle | Http Server | 12.1.3.0 |
| Oracle | Secure Global Desktop | 4.63 |
| Oracle | Secure Global Desktop | 4.71 |
| Oracle | Secure Global Desktop | 5.0 |
| Oracle | Secure Global Desktop | 5.1 |
| Canonical | Ubuntu Linux | 10.04 |
| Canonical | Ubuntu Linux | 12.04 |
| Canonical | Ubuntu Linux | 12.10 |
| Canonical | Ubuntu Linux | 13.10 |
References
- http://advisories.mageia.org/MGASA-2014-0135.htmlThird Party Advisory
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10698Third Party Advisory
- http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.htmlBroken Link, Mailing List
- http://marc.info/?l=bugtraq&m=141017844705317&w=2Issue Tracking, Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=141390017113542&w=2Issue Tracking, Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2014/Dec/23Mailing List, Third Party Advisory
- http://secunia.com/advisories/58230Not Applicable
- http://secunia.com/advisories/58915Not Applicable
- http://secunia.com/advisories/59219Not Applicable
- http://secunia.com/advisories/59315Not Applicable
- http://secunia.com/advisories/59345Not Applicable
- http://secunia.com/advisories/60536Not Applicable
- http://security.gentoo.org/glsa/glsa-201408-12.xmlThird Party Advisory
- http://support.f5.com/kb/en-us/solutions/public/15000/300/sol15320.htmlThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21668973Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21676091Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21676092Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.htmlThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/534161/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/66303Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2152-1Third Party Advisory
- http://www.vmware.com/security/advisories/VMSA-2014-0012.htmlThird Party Advisory
- https://httpd.apache.org/security/vulnerabilities_24.htmlVendor Advisory
- https://puppet.com/security/cve/cve-2014-0098Third Party Advisory
- https://support.apple.com/HT204659Third Party Advisory
- https://support.apple.com/kb/HT6535Third Party Advisory
- http://advisories.mageia.org/MGASA-2014-0135.htmlThird Party Advisory
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10698Third Party Advisory
- http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.htmlBroken Link, Mailing List
- http://marc.info/?l=bugtraq&m=141017844705317&w=2Issue Tracking, Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=141390017113542&w=2Issue Tracking, Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2014/Dec/23Mailing List, Third Party Advisory
- http://secunia.com/advisories/58230Not Applicable
- http://secunia.com/advisories/58915Not Applicable
- http://secunia.com/advisories/59219Not Applicable
- http://secunia.com/advisories/59315Not Applicable
- http://secunia.com/advisories/59345Not Applicable
- http://secunia.com/advisories/60536Not Applicable
- http://security.gentoo.org/glsa/glsa-201408-12.xmlThird Party Advisory
- http://support.f5.com/kb/en-us/solutions/public/15000/300/sol15320.htmlThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21668973Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21676091Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21676092Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.htmlThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/534161/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/66303Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2152-1Third Party Advisory
- http://www.vmware.com/security/advisories/VMSA-2014-0012.htmlThird Party Advisory
- https://httpd.apache.org/security/vulnerabilities_24.htmlVendor Advisory
- https://puppet.com/security/cve/cve-2014-0098Third Party Advisory
- https://support.apple.com/HT204659Third Party Advisory
- https://support.apple.com/kb/HT6535Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-0098?
How severe is CVE-2014-0098?
How do I fix CVE-2014-0098?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2014
- CVE-2014-0092lib/x509/verify.c in GnuTLS before 3.1.22 and 3.2.x before 3…
- CVE-2014-0093Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2,…
- CVE-2014-0094The ParametersInterceptor in Apache Struts before 2.3.16.2 a…
- CVE-2014-0095java/org/apache/coyote/ajp/AbstractAjpProcessor.java in Apac…
- CVE-2014-0096java/org/apache/catalina/servlets/DefaultServlet.java in the…
- CVE-2014-0097The ActiveDirectoryLdapAuthenticator in Spring Security 3.2.…
- CVE-2014-0099Integer overflow in java/org/apache/tomcat/util/buf/Ascii.ja…
- CVE-2014-0100Race condition in the inet_frag_intern function in net/ipv4/…
- CVE-2014-0101The sctp_sf_do_5_1D_ce function in net/sctp/sm_statefuns.c i…
- CVE-2014-0102The keyring_detect_cycle_iterator function in security/keys/…
- CVE-2014-0103WebAccess in Zarafa before 7.1.10 and WebApp before 1.6 stor…
- CVE-2014-0104In fence-agents before 4.0.17 does not verify remote SSL cer…5.9
Are you affected by CVE-2014-0098?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
