A vulnerability has been discovered in mod_auth_openidc, an OpenID Certified authentication and authorization module for the Apache HTTP server that implements the OpenID Connect Relying Party functionality:
An unauthenticated attacker could crash the Apache httpd process by sending a POST request without a Content-Type header if the 'OIDCPreservePost' directive is enabled, resulting in denial of service.
https://security-tracker.debian.org/tracker/DSA-5917-1
Continue reading...
An unauthenticated attacker could crash the Apache httpd process by sending a POST request without a Content-Type header if the 'OIDCPreservePost' directive is enabled, resulting in denial of service.
https://security-tracker.debian.org/tracker/DSA-5917-1
Continue reading...

