PublicDateAtUSN: 2014-05-23 Candidate: CVE-2014-0242 PublicDate: 2019-12-09 20:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0242 http://blog.dscpl.com.au/2014/05/security-release-for-modwsgi-version-35.html https://ubuntu.com/security/notices/USN-2222-1 Description: mod_wsgi module before 3.4 for Apache, when used in embedded mode, might allow remote attackers to obtain sensitive information via the Content-Type header which is generated from memory that may have been freed and then overwritten by a separate thread. Ubuntu-Description: Notes: Bugs: https://bugs.launchpad.net/ubuntu/+source/mod-wsgi/+bug/1322338 Priority: medium Discovered-by: Buck Golemon Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N [7.5 HIGH] Patches_mod-wsgi: upstream: https://github.com/GrahamDumpleton/mod_wsgi/commit/b0a149c1f5e569932325972e2e20176a42e43517 upstream_mod-wsgi: released (3.4) lucid_mod-wsgi: ignored (reached end-of-life) precise_mod-wsgi: released (3.3-4ubuntu0.1) saucy_mod-wsgi: not-affected (3.4-4) trusty_mod-wsgi: not-affected (3.4-4ubuntu2) trusty/esm_mod-wsgi: not-affected (3.4-4ubuntu2) devel_mod-wsgi: released (3.5-1)