Back

MEDIUM

httpd: NULL pointer dereference crash with ErrorDocument 400 pointing to a local URL-path

Published Jul 20, 2015

Description

The read_request_line function in server/protocol.c in the Apache HTTP Server 2.4.12 does not initialize the protocol structure member, which allows remote attackers to cause a denial of service (NULL pointer dereference and process crash) by sending a request that lacks a method to an installation that enables the INCLUDES filter and has an ErrorDocument 400 directive specifying a local URI.

Affected products

Remediation

Red Hat statement

This issue did not affect the versions of httpd as shipped with Red Hat Enterprise Linux 4, 5, 6, and 7; JBoss Enterprise Web Server 1 and 2; JBoss Web Server 3; and JBoss Enterprise Application Platform 6.

Metrics

References (32)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jul 20, 2015
Updated Aug 6, 2024
Reserved Nov 18, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Jul 15, 2015