PT-2013-3454 · Apache+5 · Apache Http Server+5

Publicado

2013-05-23

·

Atualizado

2024-06-15

·

CVE-2013-1896

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions prior to 2.2.25
Description The issue allows remote attackers to cause a denial of service, resulting in a segmentation fault. This can be achieved by sending a MERGE request where the URI is configured for handling by the mod dav svn module, but a certain href attribute in XML data refers to a non-DAV URI. No information is provided about the estimated number of potentially affected devices or real-world incidents.
Recommendations For Apache HTTP Server versions prior to 2.2.25, update to version 2.2.25 or later to resolve the issue. As a temporary workaround, consider restricting access to the mod dav svn module to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

ALT-PU-2015-1890
CESA-2013_1156
CVE-2013-1896
HPSBUX02927
MGASA-2013-0230
MGASA-2013-0231
OPENSUSE-SU-2024:10268-1
RHSA-2013:1133
RHSA-2013:1156
RHSA-2013:1207
RHSA-2013:1208
RHSA-2013_1156
SUSE-SU-2015:0689-1

Produtos afetados

Alt Linux
Apache Http Server
Centos
Hp-Ux
Red Hat
Suse