CVE 2014-0226
'Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service (heap-based buffer overflow), or possibly obtain sensitive credential information or execute arbitrary code, via a crafted request that triggers improper scoreboard handling within the status_handler function in modules/generators/mod_status.c and the lua_ap_scoreboard_worker function in modules/lua/lua_request.c.'
ClearCenter response
Short response
This issue was fixed in the backported fixes of versions of:
- httpd version 2.4.6-18 and later in ClearOS 7
- webconfig-httpd version 2.4.6-18 and later in ClearOS 7
- httpd version 2.2.15-31 or later in ClearOS 6
- webconfig-httpd version 2.2.15-31 or later in ClearOS 6
Long response
This issue was fixed during the maintenance cycle of ClearOS 7 and ClearOS 6. ClearOS systems that are up to date do not suffer from this vulnerability. Some vulnerability scanning software may report this bug because their only method for determining the issue is to check the http version number since the exploit requires specific web configurations and has not other means for testing vulnerability. In ClearOS, version numbers stay consistent through the product's life-cycle and will produce a false positive on this issue if the testing software considers only the http version and not the ClearOS patch level.
Resolution
If you are running ClearOS 6 or 7, please ensure that you are running the latest updates:
yum update
You may also validate your version by running:
rpm -qi httpd
You should validate that you are running:
ClearOS 7
- httpd version 2.4.6-18 or later
- webconfig-httpd version 2.4.6-18 or later
ClearOS 6
- httpd version 2.2.15-31 or later
- webconfig-httpd version 2.2.15-31 or later