PT-2013-3440 · Apache+5 · Apache Http Server+5

Published

2013-04-19

·

Updated

2022-09-14

·

CVE-2013-1862

CVSS v2.0

5.1

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.2.x through 2.2.24
Description The issue allows remote attackers to potentially execute arbitrary commands via an HTTP request containing an escape sequence for a terminal emulator. This is due to the mod rewrite module writing data to a log file without sanitizing non-printable characters.
Recommendations For Apache HTTP Server versions 2.2.x through 2.2.24, update to version 2.2.25 or later to resolve the issue.

Fix

Related Identifiers

ALT-PU-2015-1890
CESA-2013_0815
CVE-2013-1862
HPSBUX02927
MGASA-2013-0174
RHSA-2013:0815
RHSA-2013:1133
RHSA-2013:1207
RHSA-2013:1208
RHSA-2013_0815
SUSE-SU-2013_1381-1
SUSE-SU-2013_1824-1
SUSE-SU-2014_1082-1
SUSE-SU-2015:0689-1

Affected Products

Alt Linux
Apache Http Server
Centos
Hp-Ux
Red Hat
Suse