CVE-2014-8567: Red Hat Enterprise Linux Desktop

High severity, CVSS 9.4. EPSS: 3.6% chance of exploitation in the next 30 days.

The mod_auth_mellon module before 0.8.1 allows remote attackers to cause a denial of service (Apache HTTP server crash) via a crafted logout request that triggers a read of uninitialized data.

Affected products

  • Red Hat Enterprise Linux Desktop: version 6.0 only
  • Red Hat Enterprise Linux Server: version 6.0 only
  • Red Hat Enterprise Linux Server Aus: version 6.6 only
  • Red Hat Enterprise Linux Server Eus: version 6.6 only
  • Red Hat Enterprise Linux Server Tus: version 6.6 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only
  • Uninett Mod Auth Mellon: before 0.8.1 (fixed in 0.8.1)

Published 2014-11-14. Last modified 2026-06-17.