Описание
mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Directory Server 8 | httpd | Under investigation | ||
Red Hat Enterprise Linux 4 | httpd | Affected | ||
Red Hat Enterprise Linux 7 | httpd | Not affected | ||
Red Hat JBoss Enterprise Web Server 1 | httpd | Will not fix | ||
Red Hat Enterprise Linux 5 | httpd | Fixed | RHSA-2013:1156 | 13.08.2013 |
Red Hat Enterprise Linux 6 | httpd | Fixed | RHSA-2013:1156 | 13.08.2013 |
Red Hat JBoss Enterprise Application Platform 6.1 | httpd | Fixed | RHSA-2013:1209 | 04.09.2013 |
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5 | apache-commons-beanutils | Fixed | RHSA-2013:1207 | 04.09.2013 |
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5 | apache-commons-daemon-jsvc-eap6 | Fixed | RHSA-2013:1207 | 04.09.2013 |
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5 | apache-cxf | Fixed | RHSA-2013:1207 | 04.09.2013 |
Показывать по
Дополнительная информация
Статус:
EPSS
5 Medium
CVSS2
Связанные уязвимости
mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.
mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.
mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly de ...
mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.
EPSS
5 Medium
CVSS2