mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.
The MITRE CVE dictionary describes this issue as:
Find out more about CVE-2013-1896 from the MITRE CVE dictionary dictionary and NIST NVD.
Base Score | 5 |
---|---|
Base Metrics | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Access Vector | Network |
Access Complexity | Low |
Authentication | None |
Confidentiality Impact | None |
Integrity Impact | None |
Availability Impact | Partial |
Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).
Platform | Errata | Release Date |
---|---|---|
Red Hat Enterprise Linux 5 (httpd) | RHSA-2013:1156 | 2013-08-13 |
Red Hat JBoss Enterprise Web Server 2 for RHEL 6 Server (httpd) | RHSA-2013:1133 | 2013-08-05 |
Red Hat JBoss Enterprise Application Platform 6 for RHEL 6 Server (httpd) | RHSA-2013:1208 | 2013-09-04 |
Red Hat Enterprise Linux 6 (httpd) | RHSA-2013:1156 | 2013-08-13 |
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5 Server (httpd) | RHSA-2013:1207 | 2013-09-04 |
Red Hat JBoss Enterprise Web Server 2 for RHEL 5 Server (httpd) | RHSA-2013:1133 | 2013-08-05 |
Platform | Package | State |
---|---|---|
Red Hat JBoss EWS 1 | httpd | Will not fix |
Red Hat Enterprise Linux 7 | httpd | Not affected |
Red Hat Enterprise Linux 4 | httpd | Will not fix |
Red Hat Directory Server 8 | httpd | Will not fix |