CVE-2013-2249
23.07.2013, 17:20
mod_session_dbd.c in the mod_session_dbd module in the Apache HTTP Server before 2.4.5 proceeds with save operations for a session without considering the dirty flag and the requirement for a new session ID, which has unspecified impact and remote attack vectors.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| apache | http_server | 2.4.1 ≤ 𝑥 ≤ 2.4.4 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache2 |
| ||||||||||||||
| apache2-devel |
| ||||||||||||||
| apache2-doc |
| ||||||||||||||
| apache2-example-pages |
| ||||||||||||||
| apache2-prefork |
| ||||||||||||||
| apache2-utils |
| ||||||||||||||
| apache2-worker |
|
References