The cache_invalidate function in modules/cache/cache_storage.c in the mod_cache module in the Apache HTTP Server 2.4.6, when a caching forward proxy is enabled, allows remote HTTP servers to cause a denial of service (NULL pointer dereference and daemon crash) via vectors that trigger a missing hostname value.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Http_server | Apache | 2.4.6 (including) | 2.4.6 (including) |
Red Hat Enterprise Linux 7 | RedHat | httpd-0:2.4.6-18.el7_0 | * |
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6 | RedHat | httpd24-httpd-0:2.4.6-18.el6 | * |
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.4 EUS | RedHat | httpd24-httpd-0:2.4.6-18.el6 | * |
Red Hat Software Collections 1 for Red Hat Enterprise Linux 7 | RedHat | httpd24-httpd-0:2.4.6-21.el7 | * |
Apache2 | Ubuntu | upstream | * |