CVE-2014-0098
The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a denial of service (segmentation fault and daemon crash) via a crafted cookie that is not properly handled during truncation.
View on NVDSeverity
N/A
EPSS
Probability of exploitation (next 30 days): 0.4102 (41.0%)
Percentile: 97.4%
EPSS: 2026-05-06
Affects
apache:http_serveroracle:http_serveroracle:secure_global_desktopcanonical:ubuntu_linuxTechnical description
The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a denial of service (segmentation fault and daemon crash) via a crafted cookie that is not properly handled during truncation.
Published: 3/18/2014, 5:18:18 AM
Last modified: 5/6/2026, 10:30:45 PM
References
- http://advisories.mageia.org/MGASA-2014-0135.html
- http://archives.neohapsis.com/archives/bugtraq/2014-10/0101.html
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10698
- http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.html
- http://marc.info/?l=bugtraq&m=141017844705317&w=2
- http://marc.info/?l=bugtraq&m=141390017113542&w=2
- http://seclists.org/fulldisclosure/2014/Dec/23
- http://secunia.com/advisories/58230