First published: Wed Jul 10 2013(Updated: )
mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apache HTTP Server | >=2.2.0<2.2.25 | |
Apache HTTP Server | >=2.4.1<2.4.6 | |
JBoss Enterprise Application Platform | =6.0.0 | |
JBoss Enterprise Application Platform | =6.4.0 | |
Red Hat Enterprise Linux | =5.0 | |
Red Hat Enterprise Linux | =6.0 | |
Red Hat Enterprise Linux Desktop | =5.0 | |
Red Hat Enterprise Linux Desktop | =6.0 | |
Red Hat Enterprise Linux Server EUS | =5.9 | |
Red Hat Enterprise Linux Server EUS | =6.4 | |
Red Hat Enterprise Linux Server | =5.0 | |
Red Hat Enterprise Linux Server | =6.0 | |
Red Hat Enterprise Linux Server | =5.9 | |
Red Hat Enterprise Linux Server | =6.4 | |
Red Hat Enterprise Linux Workstation | =5.0 | |
Red Hat Enterprise Linux Workstation | =6.0 | |
Ubuntu | =10.04 | |
Ubuntu | =12.04 | |
Ubuntu | =12.10 | |
Ubuntu | =13.04 | |
SUSE Linux | =11.4 | |
SUSE Linux | =12.2 | |
SUSE Linux | =12.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-1896 is classified as a moderate severity vulnerability due to its potential to cause a denial of service.
To fix CVE-2013-1896, update your Apache HTTP Server to version 2.2.25 or later.
CVE-2013-1896 affects Apache HTTP Server versions prior to 2.2.25 and versions between 2.4.1 and 2.4.6.
Yes, CVE-2013-1896 can lead to service disruption by causing a segmentation fault when a MERGE request is processed.
Yes, CVE-2013-1896 is relevant for JBoss Enterprise Application Platform versions 6.0.0 and 6.4.0.