httpd: mod_proxy_fcgi handle_headers() buffer over read
Published Dec 15, 2014
5.0
MEDIUMCVSS 2.0
EPSS 10.78%
Description
The handle_headers function in mod_proxy_fcgi.c in the mod_proxy_fcgi module in the Apache HTTP Server 2.4.10 allows remote FastCGI servers to cause a denial of service (buffer over-read and daemon crash) via long response headers.
Affected products
No data.
Configuration 1
Configuration 2
- 2.4.10
Configuration 3
- 10.04
- 12.04
- 14.04
- 14.10
No data.
Red Hat Ceph Storage 1.2 for CentOS
n/a
Fixed · RHSA-2015:1858
Red Hat Common for RHEL 6
mod_proxy_fcgi-0:2.4.10-5.20150415gitd45a11f.el6cp
Fixed · RHSA-2015:1855
Red Hat Ceph Storage 1.2
mod_proxy_fcgi
Affected
Red Hat Directory Server 8
httpd
Not affected
Red Hat Enterprise Linux 5
httpd
Not affected
Red Hat Enterprise Linux 6
httpd
Not affected
Red Hat Enterprise Linux 7
httpd
Not affected
Red Hat JBoss Enterprise Application Platform 6
httpd
Not affected
Red Hat JBoss Enterprise Web Server 1
httpd
Not affected
Red Hat JBoss Enterprise Web Server 2
httpd
Not affected
Red Hat Software Collections
httpd24-httpd
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ceph Storage 1.2 for CentOS | n/a | Fixed | RHSA-2015:1858 |
| Red Hat Common for RHEL 6 | mod_proxy_fcgi-0:2.4.10-5.20150415gitd45a11f.el6cp | Fixed | RHSA-2015:1855 |
| Red Hat Ceph Storage 1.2 | mod_proxy_fcgi | Affected | n/a |
| Red Hat Directory Server 8 | httpd | Not affected | n/a |
| Red Hat Enterprise Linux 5 | httpd | Not affected | n/a |
| Red Hat Enterprise Linux 6 | httpd | Not affected | n/a |
| Red Hat Enterprise Linux 7 | httpd | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | httpd | Not affected | n/a |
| Red Hat JBoss Enterprise Web Server 1 | httpd | Not affected | n/a |
| Red Hat JBoss Enterprise Web Server 2 | httpd | Not affected | n/a |
| Red Hat Software Collections | httpd24-httpd | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Not vulnerable. This issue did not affect the versions of httpd as shipped with Red Hat Enterprise Linux 5, 6 and 7, Red Hat Software Collections 1, Red Hat JBoss Web Server 1 and 2, and Red Hat JBoss Enterprise Application Platform 6.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (51 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 10.78% (0.10783) | 95.71th | v5 (v2026.06.15) |
| Jun 15, 2026 | 10.50% (0.10499) | 95.16th | v5 (v2026.06.15) |
| Mar 8, 2026 | 41.81% (0.41813) | 97.36th | v4 (v2025.03.14) |
| Mar 4, 2026 | 19.79% (0.19785) | 95.32th | v4 (v2025.03.14) |
| Mar 1, 2026 | 9.45% (0.09449) | 92.70th | v4 (v2025.03.14) |
| Feb 4, 2026 | 19.79% (0.19785) | 95.28th | v4 (v2025.03.14) |
| Feb 1, 2026 | 9.45% (0.09449) | 92.64th | v4 (v2025.03.14) |
| Jan 4, 2026 | 19.79% (0.19785) | 95.24th | v4 (v2025.03.14) |
| Jan 1, 2026 | 9.45% (0.09449) | 92.60th | v4 (v2025.03.14) |
| Dec 28, 2025 | 19.79% (0.19785) | 95.25th | v4 (v2025.03.14) |
| Dec 27, 2025 | 14.76% (0.14762) | 94.31th | v4 (v2025.03.14) |
| Dec 4, 2025 | 19.79% (0.19785) | 95.21th | v4 (v2025.03.14) |
| Dec 1, 2025 | 9.45% (0.09449) | 92.54th | v4 (v2025.03.14) |
| Nov 4, 2025 | 19.79% (0.19785) | 95.19th | v4 (v2025.03.14) |
| Nov 1, 2025 | 9.45% (0.09449) | 92.49th | v4 (v2025.03.14) |
| Oct 28, 2025 | 19.79% (0.19785) | 95.18th | v4 (v2025.03.14) |
| Oct 27, 2025 | 14.76% (0.14762) | 94.22th | v4 (v2025.03.14) |
| Oct 4, 2025 | 19.79% (0.19785) | 95.23th | v4 (v2025.03.14) |
| Oct 1, 2025 | 9.45% (0.09449) | 92.55th | v4 (v2025.03.14) |
| Sep 4, 2025 | 14.76% (0.14762) | 94.26th | v4 (v2025.03.14) |
| Sep 1, 2025 | 6.77% (0.06772) | 90.99th | v4 (v2025.03.14) |
| Aug 6, 2025 | 14.76% (0.14762) | 94.21th | v4 (v2025.03.14) |
| Aug 1, 2025 | 6.77% (0.06772) | 90.97th | v4 (v2025.03.14) |
| Jul 30, 2025 | 14.76% (0.14762) | 94.21th | v4 (v2025.03.14) |
| Jul 5, 2025 | 19.79% (0.19785) | 95.16th | v4 (v2025.03.14) |
| Jul 1, 2025 | 9.45% (0.09449) | 92.47th | v4 (v2025.03.14) |
| Jun 7, 2025 | 19.79% (0.19785) | 95.12th | v4 (v2025.03.14) |
| Jun 1, 2025 | 9.45% (0.09449) | 92.42th | v4 (v2025.03.14) |
| May 4, 2025 | 19.79% (0.19785) | 95.08th | v4 (v2025.03.14) |
| May 1, 2025 | 9.45% (0.09449) | 92.39th | v4 (v2025.03.14) |
| Apr 9, 2025 | 19.79% (0.19785) | 94.97th | v4 (v2025.03.14) |
| Apr 8, 2025 | 9.45% (0.09449) | 92.07th | v4 (v2025.03.14) |
| Apr 5, 2025 | 19.79% (0.19785) | 94.97th | v4 (v2025.03.14) |
| Apr 4, 2025 | 9.45% (0.09449) | 92.08th | v4 (v2025.03.14) |
| Mar 30, 2025 | 19.79% (0.19785) | 94.97th | v4 (v2025.03.14) |
| Mar 29, 2025 | 24.73% (0.24733) | 93.77th | v4 (v2025.03.14) |
| Mar 28, 2025 | 19.79% (0.19785) | 94.97th | v4 (v2025.03.14) |
| Mar 27, 2025 | 9.45% (0.09449) | 91.66th | v4 (v2025.03.14) |
| Mar 25, 2025 | 19.79% (0.19785) | 94.93th | v4 (v2025.03.14) |
| Mar 24, 2025 | 9.45% (0.09449) | 92.05th | v4 (v2025.03.14) |
| Mar 17, 2025 | 19.79% (0.19785) | 94.98th | v4 (v2025.03.14) |
| Jan 31, 2025 | 5.28% (0.05281) | 93.01th | v3 (v2023.03.01) |
| Dec 17, 2024 | 4.13% (0.04134) | 92.08th | v3 (v2023.03.01) |
| Dec 12, 2024 | 1.24% (0.01238) | 86.07th | v3 (v2023.03.01) |
| Jun 10, 2024 | 0.88% (0.00876) | 82.48th | v3 (v2023.03.01) |
| Nov 22, 2023 | 0.95% (0.00953) | 81.46th | v3 (v2023.03.01) |
| Aug 22, 2023 | 0.83% (0.00829) | 79.81th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.58% (0.00585) | 74.84th | v3 (v2023.03.01) |
| Mar 6, 2023 | 5.24% (0.05242) | 89.75th | v2 (v2022.01.01) |
| Apr 1, 2022 | 5.24% (0.05242) | 88.72th | v2 (v2022.01.01) |
| Feb 4, 2022 | 5.24% (0.05242) | 75.28th | v2 (v2022.01.01) |
References (29)
- http://httpd.apache.org/security/vulnerabilities_24.html x_refsource_CONFIRMVendor Advisory
- http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html vendor-advisoryx_refsource_APPLE
- http://lists.apple.com/archives/security-announce/2015/Sep/msg00004.html vendor-advisoryx_refsource_APPLE
- http://rhn.redhat.com/errata/RHSA-2015-1855.html vendor-advisoryx_refsource_REDHAT
- http://svn.apache.org/viewvc?view=revision&revision=1638818 x_refsource_CONFIRMVendor Advisory
- http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html x_refsource_CONFIRM
- http://www.securityfocus.com/bid/71657 vdb-entryx_refsource_BID
- http://www.ubuntu.com/usn/USN-2523-1 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/errata/RHSA-2015:1858 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2014-3583 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1163555 x_refsource_CONFIRMIssue Tracking
- https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37ea993dfce68d1d%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r83109088737656fa6307bd99ab40f8ff0269ae58d3f7272d7048494a%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/ra7f6aeb28661fbf826969526585f16856abc4615877875f9d3b35ef4%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rb14daf9cc4e28d18cdc15d6a6ca74e565672fabf7ad89541071d008b%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rd336919f655b7ff309385e34a143e41c503e133da80414485b3abcc9%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://nvd.nist.gov/vuln/detail/CVE-2014-3583
- https://security.gentoo.org/glsa/201701-36 vendor-advisoryx_refsource_GENTOO
- https://support.apple.com/HT205219 x_refsource_CONFIRM
- https://support.apple.com/kb/HT205031 x_refsource_CONFIRM
- https://www.cve.org/CVERecord?id=CVE-2014-3583
Change history (0)
No recorded changes yet.