9.4
CVSSv2

CVE-2014-8567

Published: 14/11/2014 Updated: 09/07/2019
CVSS v2 Base Score: 9.4 | Impact Score: 9.2 | Exploitability Score: 10
VMScore: 837
Vector: AV:N/AC:L/Au:N/C:N/I:C/A:C

Vulnerability Summary

The mod_auth_mellon module prior to 0.8.1 allows remote malicious users to cause a denial of service (Apache HTTP server crash) via a crafted logout request that triggers a read of uninitialized data.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

uninett mod auth mellon

redhat enterprise linux server tus 6.6

redhat enterprise linux server 6.0

redhat enterprise linux server eus 6.6

redhat enterprise linux desktop 6.0

redhat enterprise linux server aus 6.6

redhat enterprise linux workstation 6.0

Vendor Advisories

It was found that uninitialized data could be accessed when processing a user's logout request By attempting to log out, a user could possibly cause the Apache HTTP Server to crash ...