CVE-2013-4352

Advisory lineage Upstream: 0 Downstream: 4
Modified
Published: 20 Jul 2014, 10:00
Last modified:06 Aug 2024, 16:38

Vulnerability Summary

Overall Risk (default)
low
22/100
CVSS Score
4.3 MEDIUM
v2.0 (nvd)
EPSS Score
24.35% HIGH
24% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

20 Jul 2014, 10:00
Published
Vulnerability first disclosed
06 Aug 2024, 16:38
Last Modified
Vulnerability information updated

Description

The cache_invalidate function in modules/cache/cache_storage.c in the mod_cache module in the Apache HTTP Server 2.4.6, when a caching forward proxy is enabled, allows remote HTTP servers to cause a denial of service (NULL pointer dereference and daemon crash) via vectors that trigger a missing hostname value.

CVSS Metrics

  • v2.0MEDIUMScore: 4.3AV:N/AC:M/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 24.35% Percentile: 96%

Affected Systems

  • UnknownHTTP Server

    2.4.6

References (16)