---
title: "CVE-2014-8109\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2014-8109?format=md
keywords: index, follow
---

# CVE-2014-8109

Publication date 29 December 2014

Last updated 24 July 2024

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

mod\_lua.c in the mod\_lua module in the Apache HTTP Server 2.3.x and 2.4.x
through 2.4.10 does not support an httpd configuration in which the same
Lua authorization provider is used with different arguments within
different contexts, which allows remote attackers to bypass intended access
restrictions in opportunistic circumstances by leveraging multiple Require
directives, as demonstrated by a configuration that specifies authorization
for one group to access a certain directory, and authorization for a second
group to access a second directory.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2014-8109?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| apache2 | 14.10 utopic | Fixed 2.4.10-1ubuntu1.1 |
| 14.04 LTS trusty | Not affected |
| 12.04 LTS precise | Not affected |
| 10.04 LTS lucid | Not affected |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2014-8109?format=md#patch-details)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

mod\_lua is in 2.4.x only
mod\_lua isn't built in trusty

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| apache2 | * Upstream:   [3f1693d](https://github.com/apache/httpd/commit/3f1693d558d0758f829c8b53993f1749ddf6ffcb) |

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8109)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2014-8109)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2014-8109)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2014-8109)

### Related Ubuntu Security Notices (USN)

+ [USN-2523-1](https://usn.ubuntu.com/USN-2523-1)
+ Apache HTTP Server vulnerabilities
+ 10 March 2015

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2014-8109>
