CVE-2013-1896
10.07.2013, 20:55
mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.Enginsight
Vendor | Product | Version |
---|---|---|
apache | http_server | 2.2.0 ≤ 𝑥 < 2.2.25 |
apache | http_server | 2.4.1 ≤ 𝑥 < 2.4.6 |
redhat | jboss_enterprise_application_platform | 6.0.0 |
redhat | jboss_enterprise_application_platform | 6.4.0 |
redhat | enterprise_linux_desktop | 5.0 |
redhat | enterprise_linux_desktop | 6.0 |
redhat | enterprise_linux_eus | 5.9 |
redhat | enterprise_linux_eus | 6.4 |
redhat | enterprise_linux_server | 5.0 |
redhat | enterprise_linux_server | 6.0 |
redhat | enterprise_linux_server_aus | 5.9 |
redhat | enterprise_linux_server_aus | 6.4 |
redhat | enterprise_linux_workstation | 5.0 |
redhat | enterprise_linux_workstation | 6.0 |
canonical | ubuntu_linux | 10.04 |
canonical | ubuntu_linux | 12.04 |
canonical | ubuntu_linux | 12.10 |
canonical | ubuntu_linux | 13.04 |
opensuse | opensuse | 11.4 |
opensuse | opensuse | 12.2 |
opensuse | opensuse | 12.3 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References