TROYANOSYVIRUS
Voltar para CVEs

CVE-2013-1896

N/A

Descricao

mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.

Detalhes CVE

Pontuacao CVSS v3.1N/A
Publicado7/10/2013
Ultima modificacao4/29/2026
Fontenvd
Avistamentos honeypot0

Produtos afetados

apache:http_servercanonical:ubuntu_linuxopensuse:opensuseredhat:enterprise_linuxredhat:enterprise_linux_desktopredhat:enterprise_linux_eusredhat:enterprise_linux_serverredhat:enterprise_linux_server_ausredhat:enterprise_linux_workstationredhat:jboss_enterprise_application_platform

Referencias

http://rhn.redhat.com/errata/RHSA-2013-1156.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2013-1207.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2013-1208.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2013-1209.html(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/55032(af854a3a-2127-422b-91ae-364da2661108)
http://support.apple.com/kb/HT6150(af854a3a-2127-422b-91ae-364da2661108)
http://www-01.ibm.com/support/docview.wss?uid=swg21644047(af854a3a-2127-422b-91ae-364da2661108)
http://www.apache.org/dist/httpd/Announcement2.2.html(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/61129(af854a3a-2127-422b-91ae-364da2661108)
http://www.ubuntu.com/usn/USN-1903-1(af854a3a-2127-422b-91ae-364da2661108)
https://httpd.apache.org/security/vulnerabilities_24.html(af854a3a-2127-422b-91ae-364da2661108)

Correlacoes IOC

Sem correlacoes registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.