Apache HTTP Server Empty Headers Denial of Service

Strike ID:
D18-0jzr1
CVSS:
7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
False Positive:
f
Variants:
1
Year:
2018

Description

This strike exploits a denial of service vulnerability in Apache HTTP Server configured with mod_cache_socache. An error in handling empty HTTP headers may lead to abnormal termination of the httpd process, resulting in a denial of service condition. An attacker can send specially crafted HTTP messaged with empty HTTP header to trigger the vulnerability.

CVE

References

Bid