Published: 16 February 2015
The lua_websocket_read function in lua_request.c in the mod_lua module in the Apache HTTP Server through 2.4.12 allows remote attackers to cause a denial of service (child-process crash) by sending a crafted WebSocket Ping frame after a Lua script has called the wsupgrade function.
mod_lua is in 2.4.x only mod_lua isn't built in trusty
Launchpad, Ubuntu, Debian
(code not built)
upstream: https://github.com/apache/httpd/commit/1f1375a2a615337d3fd1da2aad7a080243cbdcb7 (2.4)