TROYANOSYVIRUS
Volver a CVEs

CVE-2013-1896

N/A

Descripcion

mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.

Detalles CVE

Puntuacion CVSS v3.1N/A
Publicado7/10/2013
Ultima modificacion4/29/2026
Fuentenvd
Avistamientos honeypot0

Productos afectados

apache:http_servercanonical:ubuntu_linuxopensuse:opensuseredhat:enterprise_linuxredhat:enterprise_linux_desktopredhat:enterprise_linux_eusredhat:enterprise_linux_serverredhat:enterprise_linux_server_ausredhat:enterprise_linux_workstationredhat:jboss_enterprise_application_platform

Referencias

http://rhn.redhat.com/errata/RHSA-2013-1156.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2013-1207.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2013-1208.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2013-1209.html(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/55032(af854a3a-2127-422b-91ae-364da2661108)
http://support.apple.com/kb/HT6150(af854a3a-2127-422b-91ae-364da2661108)
http://www-01.ibm.com/support/docview.wss?uid=swg21644047(af854a3a-2127-422b-91ae-364da2661108)
http://www.apache.org/dist/httpd/Announcement2.2.html(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/61129(af854a3a-2127-422b-91ae-364da2661108)
http://www.ubuntu.com/usn/USN-1903-1(af854a3a-2127-422b-91ae-364da2661108)
https://httpd.apache.org/security/vulnerabilities_24.html(af854a3a-2127-422b-91ae-364da2661108)

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.