Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g852-xcg2-2w9v

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью

Описание

mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.

mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.

Ссылки

EPSS

Процентиль: 96%
0.29859
Средний

Связанные уязвимости

ubuntu
около 12 лет назад

mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.

redhat
около 12 лет назад

mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.

nvd
около 12 лет назад

mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.

debian
около 12 лет назад

mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly de ...

oracle-oval
около 12 лет назад

ELSA-2013-1156: httpd security update (MODERATE)

EPSS

Процентиль: 96%
0.29859
Средний