Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1121519 - (CVE-2014-3523) CVE-2014-3523 httpd: WinNT MPM denial of service
CVE-2014-3523 httpd: WinNT MPM denial of service
Status: CLOSED NOTABUG
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20140715,repor...
: Security
Depends On:
Blocks: 1120623 1121528 1395463
  Show dependency treegraph
 
Reported: 2014-07-21 02:46 EDT by Grant Murphy
Modified: 2016-12-15 17:13 EST (History)
26 users (show)

See Also:
Fixed In Version: httpd 2.4.10
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2014-07-22 04:44:22 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
JBoss Issue Tracker JCSP-95 Blocker Closed CVE-2014-3523 httpd: WinNT MPM denial of service 2018-08-09 04:26 EDT
JBoss Issue Tracker JWS-433 Major Closed CVE-2014-3523 httpd: WinNT MPM denial of service 2018-08-09 04:26 EDT
Red Hat Product Errata RHSA-2016:2957 normal SHIPPED_LIVE Important: Red Hat JBoss Core Services Apache HTTP 2.4.23 Release 2016-12-15 22:11:19 EST

  None (edit)
Description Grant Murphy 2014-07-21 02:46:47 EDT
The following flaw has been fixed in the Apache HTTP Server:

"A flaw was found in the WinNT MPM in httpd versions 2.4.1 to 2.4.9, when using the default AcceptFilter for that platform. A remote attacker could send carefully crafted requests that would leak memory and eventually lead to a denial of service against the server."

External References:

http://httpd.apache.org/security/vulnerabilities_24.html
Comment 1 Grant Murphy 2014-07-22 03:54:50 EDT
Upstream fix: 

https://github.com/apache/httpd/commit/c17f0b89657cf03318fe2b624adc92cae477f81b

Code not present in 2.2
Comment 2 Grant Murphy 2014-07-22 04:44:22 EDT
Statement:

Not affected. This issue did not affect the versions of httpd as shipped with Red Hat Enterprise Linux 5, 6 and 7, Red Hat JBoss Web Server 1 and 2, and Red Hat JBoss Enterprise Application Platform 5 and 6. This flaw only affects httpd running on Microsoft Windows. Red Hat JBoss Web Server 1 and 2, and Red Hat JBoss Enterprise Application Platform 5 and 6 can be run on Microsoft Windows. However, these products provide httpd 2.2, which is not affected by this flaw.
Comment 3 Tomas Hoger 2014-07-23 02:47:29 EDT
Upstream commit:
http://svn.apache.org/viewvc?view=revision&revision=1610652
Comment 4 JBoss JIRA Server 2016-09-06 09:20:40 EDT
Michal Karm Babacek <mbabacek@redhat.com> updated the status of jira JWS-433 to Resolved
Comment 7 errata-xmlrpc 2016-12-15 17:13:29 EST
This issue has been addressed in the following products:



Via RHSA-2016:2957 https://rhn.redhat.com/errata/RHSA-2016-2957.html

Note You need to log in before you can comment on or make changes to this bug.