CVE-2013-1896
MEDIUM severity · CVSS 4.3
4.3CVSS MEDIUM
Summary
mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.
Impact & exploitability
Attack vectorNetwork
Attack complexity—
Privileges required—
User interaction—
Confidentiality impactNone
Integrity impactNone
Availability impact—
Exploit probability (EPSS)29%
AV:N/AC:M/Au:N/C:N/I:N/A:P
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Additional information
- NVD record
- http://lists.opensuse.org/opensuse-updates/2013-08/msg00026.htmlAdvisory
- http://lists.opensuse.org/opensuse-updates/2013-08/msg00029.htmlAdvisory
- http://lists.opensuse.org/opensuse-updates/2013-08/msg00030.htmlAdvisory
- http://rhn.redhat.com/errata/RHSA-2013-1156.htmlAdvisory
- http://rhn.redhat.com/errata/RHSA-2013-1207.htmlAdvisory
- http://rhn.redhat.com/errata/RHSA-2013-1208.htmlAdvisory
- http://rhn.redhat.com/errata/RHSA-2013-1209.htmlAdvisory
- http://secunia.com/advisories/55032