PT-2013-3454 · Apache+5 · Apache Http Server+5

Published

2013-05-23

·

Updated

2024-06-15

·

CVE-2013-1896

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions prior to 2.2.25
Description The issue allows remote attackers to cause a denial of service, resulting in a segmentation fault. This can be achieved by sending a MERGE request where the URI is configured for handling by the mod dav svn module, but a certain href attribute in XML data refers to a non-DAV URI. No information is provided about the estimated number of potentially affected devices or real-world incidents.
Recommendations For Apache HTTP Server versions prior to 2.2.25, update to version 2.2.25 or later to resolve the issue. As a temporary workaround, consider restricting access to the mod dav svn module to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALT-PU-2015-1890
CESA-2013_1156
CVE-2013-1896
HPSBUX02927
MGASA-2013-0230
MGASA-2013-0231
OPENSUSE-SU-2024:10268-1
RHSA-2013:1133
RHSA-2013:1156
RHSA-2013:1207
RHSA-2013:1208
RHSA-2013_1156
SUSE-SU-2015:0689-1

Affected Products

Alt Linux
Apache Http Server
Centos
Hp-Ux
Red Hat
Suse