CVE-2014-3581: Apache HTTP Server
Medium severity, CVSS 5.0. EPSS: 13.6% chance of exploitation in the next 30 days.
The cache_merge_headers_out function in modules/cache/cache_util.c in the mod_cache module in the Apache HTTP Server before 2.4.11 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty HTTP Content-Type header.
Affected products
- Apache HTTP Server: version 2.4.1 only; version 2.4.2 only; version 2.4.3 only; version 2.4.4 only; version 2.4.6 only; version 2.4.7 only; …
- Canonical Ubuntu Linux: version 10.04 only; version 12.04 only; version 14.04 only; version 14.10 only
- Oracle Enterprise Manager Ops Center: before 12.1.4 (fixed in 12.1.4); version 12.2.0 only; version 12.2.1 only; version 12.3.0 only
- Oracle Linux: version 6 only
- Red Hat Enterprise Linux Desktop: version 7.0 only
- Red Hat Enterprise Linux Eus: version 7.3 only; version 7.4 only; version 7.5 only; version 7.6 only; version 7.7 only
- Red Hat Enterprise Linux Server: version 7.0 only
- Red Hat Enterprise Linux Server Aus: version 7.3 only; version 7.4 only; version 7.6 only; version 7.7 only
- Red Hat Enterprise Linux Server Tus: version 7.3 only; version 7.6 only; version 7.7 only
Published 2014-10-10. Last modified 2026-06-17.