Description
The ap_read_request function in server/protocol.c in the Apache HTTP Server 2.2.x before 2.2.15, when a multithreaded MPM is used, does not properly handle headers in subrequests in certain circumstances involving a parent request that has a body, which might allow remote attackers to obtain sensitive information via a crafted request that triggers access to memory locations associated with an earlier request.
Remediation
References
Related Vulnerabilities
AngularJS Inefficient Regular Expression Complexity Vulnerability (CVE-2023-26116)
Oracle Application Server Other Vulnerability (CVE-2002-0947)
Jboss EAP Improper Input Validation Vulnerability (CVE-2014-0034)
WordPress Plugin WP STAGING WordPress Backup-Migration Backup Restore Information Disclosure (3.4.3)