Apache HTTP Server releases before 2.4.10 are affected by three vulnerabilities in optional modules. mod_status contains a race condition, tracked as CVE-2014-0226, in scoreboard handling that can trigger a heap-based buffer overflow through crafted requests; the flaw can cause denial of service and potentially disclose sensitive credentials or enable arbitrary code execution. mod_deflate is vulnerable to resource exhaustion (CVE-2014-0118) when request-body decompression processes compressed input that expands disproportionately.
The mod_cgid module also lacks a timeout when communicating with CGI programs that do not read standard input, enabling a remote attacker to hang a server process (CVE-2014-0231). Apache HTTP Server 2.4.x deployments should upgrade to 2.4.10 or later, and Mageia issued updated Apache packages through advisories MGASA-2014-0304 and MGASA-2014-0305 to address these security issues.

See affected versions and whether adversaries are exploiting it.
20 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important advisory RHSA-2014:1020 for JBoss EAP 6.3.0 on RHEL 6. The update addressed Apache httpd CVE-2014-0118, CVE-2014-0226, and CVE-2014-0231, Netty CVE-2014-0193, and the JBoss SimpleSecurityManager authorization-bypass flaw CVE-2014-3472.
Red Hat issued Important advisory RHSA-2014:1019, updating JBoss Enterprise Application Platform 6.3.0 packages for RHEL 5. The update addressed Apache httpd flaws CVE-2014-0118, CVE-2014-0226, and CVE-2014-0231, as well as Netty denial of service CVE-2014-0193 and JBoss role-check authorization bypass CVE-2014-3472.
Red Hat released RHSA-2014:0920 for affected RHEL 5 and 6 httpd packages and RHSA-2014:0921 for RHEL 7, remediating the Apache mod_status race-condition and heap-overflow vulnerability CVE-2014-0226.
Red Hat released RHSA-2014:0920 for RHEL 5 and 6 and RHSA-2014:0921 for RHEL 7, fixing the Apache mod_cgid denial-of-service vulnerability CVE-2014-0231 in affected httpd packages.
Red Hat released RHSA-2014:0920 for affected RHEL 5 and 6 httpd packages and RHSA-2014:0921 for RHEL 7, fixing the mod_deflate resource-exhaustion flaw CVE-2014-0118.
CVE-2014-0231 was published for Apache HTTP Server mod_cgid versions before 2.4.10. A request to a CGI script that does not read standard input can hang a server process because mod_cgid lacked a timeout mechanism.
CVE-2014-0226 was published for a race condition in Apache HTTP Server mod_status before version 2.4.10. Crafted requests can trigger improper scoreboard handling and a heap-based buffer overflow, potentially causing denial of service, credential exposure, or code execution.
CVE-2014-0118 was published, documenting a mod_deflate flaw in Apache HTTP Server versions before 2.4.10. Crafted compressed request data can cause disproportionate decompression and resource-exhaustion denial of service when request-body decompression is enabled.
CVE-2014-0117 was published for a denial-of-service flaw in Apache HTTP Server mod_proxy 2.4.x before 2.4.10. When configured as a reverse proxy, a crafted HTTP Connection header can crash an Apache child process.
Red Hat resolved Bugzilla issue 1076652 by upgrading wsdl4j, including wsdl4j-wsdl4j-1.6.3.redhat_1-1 and wsdl4j-eap6-1.6.3-1.redhat_1.1.ep6.el6. The update was verified in JBoss EAP 6.3.0.ER10 and closed as ERRATA under RHSA-2014:1020.
Red Hat resolved Bugzilla bug 1079429 by upgrading the Eclipse JDT Core Compiler (ecj-eap6) component for RHEL 6. The upgrade was verified in JBoss EAP 6.3.0.ER10 and closed as ERRATA, with RHSA-2014:1020 identified for updated files and advisory information.
Apple released security updates for OS X Yosemite 10.10 through 10.10.2, Mountain Lion 10.8.5, and Mavericks 10.9.5. The updates remediated numerous vulnerabilities across components including the kernel, IOHIDFamily, OpenSSL, PHP, WebKit, and code-signing validation.
Red Hat remediated the Apache mod_deflate denial-of-service vulnerability CVE-2014-0118 in Software Collections 1 and RHEL 6.4 EUS through RHSA-2014:0922, JBoss EAP 6.3.0 through RHSA-2014:1021, and JBoss Enterprise Web Server/JBoss Web Server through RHSA-2014:1086, RHSA-2014:1087, and RHSA-2014:1088.
Red Hat addressed the Apache mod_cgid denial-of-service flaw CVE-2014-0231 in Software Collections 1 through RHSA-2014:0922, JBoss EAP 6.3.0 through RHSA-2014:1021, and JBoss Enterprise Web Server/JBoss Web Server through RHSA-2014:1086, RHSA-2014:1087, and RHSA-2014:1088.
Red Hat addressed the Apache mod_status heap-overflow vulnerability CVE-2014-0226 in Red Hat Software Collections through RHSA-2014:0922, JBoss EAP 6.3.0 through RHSA-2014:1021, and JBoss Web Server through RHSA-2014:1086, RHSA-2014:1087, and RHSA-2014:1088.
Mageia published advisory MGASA-2014-0305 for an updated Apache package that fixes security vulnerabilities.
Mageia published advisory MGASA-2014-0304 for an updated Apache package that fixes security vulnerabilities.
Red Hat resolved Bugzilla bug 1086792 by upgrading JBoss VFS from the 3.2.4.Final_redhat_1 package build to 3.2.5.Final_redhat_1 in EAP 6.3.0.ER10. The issue was closed as ERRATA, with RHSA-2014:1020 identified as containing the updated files and remediation information.
Fedora released httpd-2.4.10-1.fc20 and httpd-2.4.10-1.fc19 to the Fedora 20 and Fedora 19 stable repositories, respectively, addressing the Apache mod_status heap-based buffer-overflow vulnerability CVE-2014-0226.
Fedora shipped httpd-2.4.10-1.fc20 to the Fedora 20 stable repository, remediating the Apache mod_cgid denial-of-service flaw CVE-2014-0231. The same package was later shipped to Fedora 19 stable.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
33 references tracked. Mallory keeps watching after this page renders.
cve.org
Open sourcecve.org
Open sourcerhn.redhat.com
Open sourcecve.org
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcerhn.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.