DEBIAN-CVE-2014-0098
Advisory lineage Upstream: 1 Downstream: 0
Upstream
Published: 18 Mar 2014, 05:18
Last modified:28 Apr 2026, 20:12
Vulnerability Summary
Overall Risk (default)
minimal
0/100 CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
18 Mar 2014, 05:18
Published
Vulnerability first disclosed
28 Apr 2026, 20:12
Last Modified
Vulnerability information updated
Description
The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a denial of service (segmentation fault and daemon crash) via a crafted cookie that is not properly handled during truncation.
Affected Systems
- debian•apache2
< 2.4.9-1 | < 2.4.9-1 | < 2.4.9-1 | < 2.4.9-1