PublicDateAtUSN: 2014-07-20 Candidate: CVE-2014-0117 PublicDate: 2014-07-20 11:12:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0117 http://httpd.apache.org/security/vulnerabilities_24.html https://ubuntu.com/security/notices/USN-2299-1 Description: The mod_proxy module in the Apache HTTP Server 2.4.x before 2.4.10, when a reverse proxy is enabled, allows remote attackers to cause a denial of service (child-process crash) via a crafted HTTP Connection header. Ubuntu-Description: Notes: mdeslar> PoC: http://seclists.org/fulldisclosure/2014/Jul/117 Bugs: Priority: medium Discovered-by: Marek Kroemeke Assigned-to: mdeslaur CVSS: Patches_apache2: upstream: http://svn.apache.org/viewvc?view=revision&revision=1610737 (2.4.x) upstream_apache2: released (2.4.10) lucid_apache2: not-affected (2.2.14-5ubuntu8.13) precise_apache2: not-affected (2.2.22-1ubuntu1.6) trusty_apache2: released (2.4.7-1ubuntu4.1) trusty/esm_apache2: released (2.4.7-1ubuntu4.1) devel_apache2: released (2.4.10-1ubuntu1)