Back

MEDIUM

httpd: Possible mod_lua crash due to websocket bug

Published Mar 8, 2015

Description

The lua_websocket_read function in lua_request.c in the mod_lua module in the Apache HTTP Server through 2.4.12 allows remote attackers to cause a denial of service (child-process crash) by sending a crafted WebSocket Ping frame after a Lua script has called the wsupgrade function.

Affected products

Remediation

Red Hat statement

This issue did not affect the version of httpd package as shipped with Red Hat Enterprise Linux 5, 6 and 7.

Metrics

References (33)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 8, 2015
Updated Aug 6, 2024
Reserved Nov 18, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Mar 10, 2015