The mod_auth_mellon module before 0.8.1 allows remote attackers to obtain...
Vulnerability Description
The mod_auth_mellon module before 0.8.1 allows remote attackers to obtain sensitive information or cause a denial of service (segmentation fault) via unspecified vectors related to a "session overflow" involving "sessions overlapping in memory."
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-8566
Credits & Attribution
No credits recorded in the NVD database.
References
- http://linux.oracle.com/errata/ELSA-2014-1803.html
- http://rhn.redhat.com/errata/RHSA-2014-1803.html
- https://github.com/UNINETT/mod_auth_mellon/releases/tag/v0.8.1
- http://secunia.com/advisories/62094
- http://secunia.com/advisories/62125
- https://postlister.uninett.no/sympa/arc/modmellon/2014-11/msg00000.html
More from uninett
View All →Affected Vendor
uninett
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.