Description
The read_request_line function in server/protocol.c in the Apache HTTP Server 2.4.12 does not initialize the protocol structure member, which allows remote attackers to cause a denial of service (NULL pointer dereference and process crash) by sending a request that lacks a method to an installation that enables the INCLUDES filter and has an ErrorDocument 400 directive specifying a local URI.
Remediation
References
Related Vulnerabilities
WordPress Plugin Ceceppa Multilingua Cross-Site Scripting (1.5.17)
WordPress Plugin LearnPress-WordPress LMS Security Bypass (3.2.6.8)
WordPress Plugin IQ Testimonials Arbitrary File Upload (2.2.7)
Joomla! Core 3.x.x Multiple Cross-Site Scripting Vulnerabilities (3.0.0 - 3.9.3)
WordPress Plugin Hero Maps Premium Cross-Site Scripting (2.2.1)