Описание
The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before 2.4.8 does not properly remove whitespace characters from CDATA sections, which allows remote attackers to cause a denial of service (daemon crash) via a crafted DAV WRITE request.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Directory Server 8 | httpd | Affected | ||
Red Hat Enterprise Linux 7 | httpd | Not affected | ||
Red Hat JBoss Enterprise Application Platform 5 | httpd | Will not fix | ||
Red Hat JBoss Enterprise Web Server 1 | httpd | Will not fix | ||
Red Hat JBoss Enterprise Web Server 1 | others | Not affected | ||
Red Hat Software Collections | httpd24-httpd | Affected | ||
Red Hat Enterprise Linux 5 | httpd | Fixed | RHSA-2014:0369 | 03.04.2014 |
Red Hat Enterprise Linux 6 | httpd | Fixed | RHSA-2014:0370 | 03.04.2014 |
Red Hat JBoss Enterprise Application Platform 6.2 | Fixed | RHSA-2014:0825 | 01.07.2014 | |
Red Hat JBoss Enterprise Application Platform 6.2 for RHEL 5 | httpd | Fixed | RHSA-2014:0826 | 01.07.2014 |
Показывать по
Дополнительная информация
Статус:
EPSS
4.3 Medium
CVSS2
Связанные уязвимости
The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before 2.4.8 does not properly remove whitespace characters from CDATA sections, which allows remote attackers to cause a denial of service (daemon crash) via a crafted DAV WRITE request.
The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before 2.4.8 does not properly remove whitespace characters from CDATA sections, which allows remote attackers to cause a denial of service (daemon crash) via a crafted DAV WRITE request.
The dav_xml_get_cdata function in main/util.c in the mod_dav module in ...
The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before 2.4.8 does not properly remove whitespace characters from CDATA sections, which allows remote attackers to cause a denial of service (daemon crash) via a crafted DAV WRITE request.
EPSS
4.3 Medium
CVSS2