CVE-2014-0118
apache2 - security update
EPSS 37.2%
描述
The deflate_in_filter function in mod_deflate.c in the mod_deflate module in the Apache HTTP Server before 2.4.10, when request body decompression is enabled, allows remote attackers to cause a denial of service (resource consumption) via crafted request data that decompresses to a much larger size.
如何修補 CVE-2014-0118
要修補 CVE-2014-0118,請將受影響套件升級到下列已修補版本。
- Debian/apache2—升級至 2.4.10-1 或更新版本
- Debian/apache2—升級至 2.2.22-13+deb7u3 或更新版本
CVE-2014-0118 正在被利用嗎?
中等 — EPSS 為 37.2%,可持續追蹤但非最高優先。
受影響套件(2)
- from 0, < 2.4.10-1
- from 0, < 2.2.22-13+deb7u3