mod_wsgi: information leak
Published Dec 9, 2019
7.5
HIGHCVSS 3.1
EPSS 8.53%
Description
mod_wsgi module before 3.4 for Apache, when used in embedded mode, might allow remote attackers to obtain sensitive information via the Content-Type header which is generated from memory that may have been freed and then overwritten by a separate thread.
Affected products
-
- Version before 3.4StatusaffectedConstraints-
- Version
No data.
Red Hat Enterprise Linux 6
mod_wsgi-0:3.2-6.el6_5
Fixed · RHSA-2014:0788
Red Hat Enterprise Linux 7
mod_wsgi
Not affected
Red Hat OpenShift Enterprise 2
python27-mod_wsgi
Not affected
Red Hat Satellite 5
mod_wsgi
Will not fix
Red Hat Satellite 6
mod_wsgi
Not affected
Red Hat Software Collections
python27-mod_wsgi
Not affected
Red Hat Software Collections
python33-mod_wsgi
Not affected
Red Hat Subscription Asset Manager
mod_wsgi
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | mod_wsgi-0:3.2-6.el6_5 | Fixed | RHSA-2014:0788 |
| Red Hat Enterprise Linux 7 | mod_wsgi | Not affected | n/a |
| Red Hat OpenShift Enterprise 2 | python27-mod_wsgi | Not affected | n/a |
| Red Hat Satellite 5 | mod_wsgi | Will not fix | n/a |
| Red Hat Satellite 6 | mod_wsgi | Not affected | n/a |
| Red Hat Software Collections | python27-mod_wsgi | Not affected | n/a |
| Red Hat Software Collections | python33-mod_wsgi | Not affected | n/a |
| Red Hat Subscription Asset Manager | mod_wsgi | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Update Infrastructure 2.1.3 is now in Production 2 Phase of the support and maintenance life cycle. This has been rated as having Moderate security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Update Infrastructure Life Cycle: https://access.redhat.com/support/policy/updates/rhui.
References (8)
- http://blog.dscpl.com.au/2014/05/security-release-for-modwsgi-version-35.html x_refsource_MISCRelease NotesThird Party Advisory
- http://modwsgi.readthedocs.org/en/latest/release-notes/version-3.4.html x_refsource_MISCRelease NotesVendor Advisory
- http://www.openwall.com/lists/oss-security/2014/05/21/1 x_refsource_MISCMailing List
- http://www.securityfocus.com/bid/67534 x_refsource_MISCThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2014-0242 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1101873 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2014-0242
- https://www.cve.org/CVERecord?id=CVE-2014-0242
| Link | Providers | Tags |
|---|---|---|
| http://blog.dscpl.com.au/2014/05/security-release-for-modwsgi-version-35.html | x_refsource_MISCRelease NotesThird Party Advisory | |
| http://modwsgi.readthedocs.org/en/latest/release-notes/version-3.4.html | x_refsource_MISCRelease NotesVendor Advisory | |
| http://www.openwall.com/lists/oss-security/2014/05/21/1 | x_refsource_MISCMailing List | |
| http://www.securityfocus.com/bid/67534 | x_refsource_MISCThird Party AdvisoryVDB Entry | |
| https://access.redhat.com/security/cve/CVE-2014-0242 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1101873 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2014-0242 | ||
| https://www.cve.org/CVERecord?id=CVE-2014-0242 |
Change history (0)
No recorded changes yet.