Back to Database
Status published
Critical
CVE-2014-8567
The mod_auth_mellon module before 0.8.1 allows remote attackers to cause...
Vulnerability Description
The mod_auth_mellon module before 0.8.1 allows remote attackers to cause a denial of service (Apache HTTP server crash) via a crafted logout request that triggers a read of uninitialized data.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-8567
Credits & Attribution
No credits recorded in the NVD database.
References
- http://linux.oracle.com/errata/ELSA-2014-1803.html
- http://rhn.redhat.com/errata/RHSA-2014-1803.html
- http://secunia.com/advisories/62094
- http://secunia.com/advisories/62125
- https://postlister.uninett.no/sympa/arc/modmellon/2014-11/msg00000.html
- https://github.com/UNINETT/mod_auth_mellon/commit/0f5b4fd860fa7e3a6c47201637aab05395f32647
More from uninett
View All →CVE-2019-3878
A vulnerability was found in mod_auth_mellon before v0.14.2. If Apache...
High
8.1
CVE-2019-3877
A vulnerability was found in mod_auth_mellon before v0.14.2. An open...
Medium
5.8
CVE-2017-6807
mod_auth_mellon before 0.13.1 is vulnerable to a Cross-Site Session Transfer...
Medium
6.1
CVE-2014-8566
The mod_auth_mellon module before 0.8.1 allows remote attackers to obtain...
Medium
6.4
CVE-2012-4566
The DTLS support in radsecproxy before 1.6.2 does not properly...
Medium
6.4
Affected Vendor
uninett
View all reports →Affected Software
mod auth mellon, enterprise linux desktop, enterprise linux server, enterprise linux server aus, enterprise linux server eus, enterprise linux server tus, enterprise linux workstation
Vulnerable Versions:
0, 6.0, 6.6
Timeline
Official Publish:
November 14th, 2014
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.