RULE(RULE ID:311381)

Rule General Information
Release Date: 2015-11-02
Rule Name: Apache HTTP Server Mod_deflate Denial of Service Vulnerability -2 (CVE-2014-0118)
Severity:
CVE ID:
Rule Protection Details
Description: The deflate_in_filter function in mod_deflate.c in the mod_deflate module in the Apache HTTP Server before 2.4.10, when request body decompression is enabled, allows remote attackers to cause a denial of service (resource consumption) via crafted request data that decompresses to a much larger size.
Impact: An attacker can launch a denial of service attack by exploiting the vulnerability successfully.
Affected OS: Solaris, FreeBSD, Windows, Linux, Other Unix, Mac OS
Reference: SecurityFocusBID:68745
Solutions
More advisories have been published on the website, please visit for more suggestions:
http://httpd.apache.org/security/vulnerabilities_24.html