CVE-2013-1896: Medium severity apache http server vulnerability
moddav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the moddavsvn module, but a certain href attribute in XML data refers to a non-DAV URI.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1896?
CVE-2013-1896 is classified as a moderate severity vulnerability due to its potential to cause a denial of service.
How do I fix CVE-2013-1896?
To fix CVE-2013-1896, update your Apache HTTP Server to version 2.2.25 or later.
Which software versions are affected by CVE-2013-1896?
CVE-2013-1896 affects Apache HTTP Server versions prior to 2.2.25 and versions between 2.4.1 and 2.4.6.
Can CVE-2013-1896 lead to service disruption?
Yes, CVE-2013-1896 can lead to service disruption by causing a segmentation fault when a MERGE request is processed.
Is CVE-2013-1896 relevant for JBoss Enterprise Application Platform?
Yes, CVE-2013-1896 is relevant for JBoss Enterprise Application Platform versions 6.0.0 and 6.4.0.