PublicDateAtUSN: 2014-07-20 Candidate: CVE-2014-0231 PublicDate: 2014-07-20 11:12:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0231 https://ubuntu.com/security/notices/USN-2299-1 Description: The mod_cgid module in the Apache HTTP Server before 2.4.10 does not have a timeout mechanism, which allows remote attackers to cause a denial of service (process hang) via a request to a CGI script that does not read from its stdin file descriptor. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Rainer Jung Assigned-to: mdeslaur CVSS: Patches_apache2: upstream: http://svn.apache.org/viewvc?view=revision&revision=1610512 (2.4.x) upstream: http://svn.apache.org/viewvc?view=revision&revision=1610522 (2.4.x) (partial) upstream: http://svn.apache.org/viewvc?view=revision&revision=1611185 (2.2.x) upstream_apache2: released (2.4.10) lucid_apache2: released (2.2.14-5ubuntu8.14) precise_apache2: released (2.2.22-1ubuntu1.7) trusty_apache2: released (2.4.7-1ubuntu4.1) trusty/esm_apache2: released (2.4.7-1ubuntu4.1) devel_apache2: released (2.4.10-1ubuntu1)