CVE-2013-1862
MEDIUM severity · CVSS 5.1
5.1CVSS MEDIUM
Summary
mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containing an escape sequence for a terminal emulator.
Impact & exploitability
Attack vectorNetwork
Attack complexityHigh
Privileges required—
User interaction—
Confidentiality impact—
Integrity impact—
Availability impact—
Exploit probability (EPSS)25%
AV:N/AC:H/Au:N/C:P/I:P/A:P
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Official patch: http://people.apache.org/~jorton/mod_rewrite-CVE-2013-1862.patch ↗
Additional information
- NVD record
- http://people.apache.org/~jorton/mod_rewrite-CVE-2013-1862.patchPatch
- http://lists.opensuse.org/opensuse-updates/2013-08/msg00026.htmlAdvisory
- http://lists.opensuse.org/opensuse-updates/2013-08/msg00029.htmlAdvisory
- http://lists.opensuse.org/opensuse-updates/2013-08/msg00030.htmlAdvisory
- http://rhn.redhat.com/errata/RHSA-2013-0815.htmlAdvisory
- http://rhn.redhat.com/errata/RHSA-2013-1207.htmlAdvisory
- http://rhn.redhat.com/errata/RHSA-2013-1208.htmlAdvisory
- http://rhn.redhat.com/errata/RHSA-2013-1209.htmlAdvisory