The read_request_line function in server/protocol.c in the Apache HTTP Server 2.4.12 does not initialize the protocol structure member, which allows remote attackers to cause a denial of service (NULL pointer dereference and process crash) by sending a request that lacks a method to an installation that enables the INCLUDES filter and has an ErrorDocument 400 directive specifying a local URI.
We have discovered 610,257 live websites that are affected by CVE-2015-0253.
| Product | |
| Category | Web Servers |
| Vulnerable Domains | 610,257 live websites (24% of Apache install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 72 versions ( 59% of all versions) |
| 145,259 websites | |
| 107,325 websites | |
| 49,462 websites | |
| 39,779 websites | |
| 25,065 websites | |
| 24,476 websites | |
| 23,648 websites | |
| 16,117 websites | |
| 15,248 websites | |
| 14,210 websites |
| .com | 281,592 websites |
| .de | 35,504 websites |
| .net | 24,600 websites |
| .ru | 20,895 websites |
| .org | 20,440 websites |
| .nl | 18,669 websites |
| .cz | 13,151 websites |
| .it | 12,311 websites |
| .info | 11,921 websites |
| .jp | 11,366 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****.***********.com | *** | ||
| ******************.com | *,*** | ||
| *******.**.com | *,*** | ||
| *********.******.net | *,*** | ||
| ****.com | *,*** | ||
| ********.com | *,*** | ||
| ****.**.pl | *,*** | ||
| ******.com | *,*** | ||
| ********.********.de | *,*** | ||
| ******.****************.com | *,*** |