CVE-2013-5704

The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding.  NOTE: the vendor states "this is not a security issue in httpd as such."
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 98%
VendorProductVersion
apachehttp_server
2.2.0
apachehttp_server
2.2.2
apachehttp_server
2.2.3
apachehttp_server
2.2.4
apachehttp_server
2.2.5
apachehttp_server
2.2.6
apachehttp_server
2.2.8
apachehttp_server
2.2.9
apachehttp_server
2.2.10
apachehttp_server
2.2.11
apachehttp_server
2.2.12
apachehttp_server
2.2.13
apachehttp_server
2.2.14
apachehttp_server
2.2.15
apachehttp_server
2.2.16
apachehttp_server
2.2.17
apachehttp_server
2.2.18
apachehttp_server
2.2.19
apachehttp_server
2.2.20
apachehttp_server
2.2.21
apachehttp_server
2.2.22
apachehttp_server
2.2.23
apachehttp_server
2.2.24
apachehttp_server
2.2.25
apachehttp_server
2.2.26
apachehttp_server
2.2.27
apachehttp_server
2.4.1
apachehttp_server
2.4.2
apachehttp_server
2.4.3
apachehttp_server
2.4.4
apachehttp_server
2.4.6
apachehttp_server
2.4.7
apachehttp_server
2.4.9
apachehttp_server
2.4.10
redhatenterprise_linux_desktop
6.0
redhatenterprise_linux_desktop
7.0
redhatenterprise_linux_eus
7.3
redhatenterprise_linux_eus
7.4
redhatenterprise_linux_eus
7.5
redhatenterprise_linux_eus
7.6
redhatenterprise_linux_eus
7.7
redhatenterprise_linux_server
6.0
redhatenterprise_linux_server
7.0
redhatenterprise_linux_server_aus
7.3
redhatenterprise_linux_server_aus
7.4
redhatenterprise_linux_server_aus
7.6
redhatenterprise_linux_server_aus
7.7
redhatenterprise_linux_server_tus
7.3
redhatenterprise_linux_server_tus
7.6
redhatenterprise_linux_server_tus
7.7
redhatenterprise_linux_workstation
6.0
redhatenterprise_linux_workstation
7.0
redhatjboss_enterprise_web_server
3.0.0
redhatjboss_enterprise_web_server
2.0.0
oracleenterprise_manager_ops_center
𝑥
< 12.1.4
oracleenterprise_manager_ops_center
12.1.4
oracleenterprise_manager_ops_center
12.2.0
oracleenterprise_manager_ops_center
12.2.1
oracleenterprise_manager_ops_center
12.3.0
oraclehttp_server
10.1.3.5.0
oraclehttp_server
11.1.1.7.0
oraclehttp_server
12.1.2.0
oraclehttp_server
12.1.3.0
oraclesolaris
11.2
applemac_os_x
𝑥
< 10.10.4
applemac_os_x_server
𝑥
< 5.0.3
canonicalubuntu_linux
10.04
canonicalubuntu_linux
12.04
canonicalubuntu_linux
14.04
canonicalubuntu_linux
14.10
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
apache2
bullseye
2.4.62-1~deb11u1
fixed
bullseye (security)
2.4.62-1~deb11u2
fixed
bookworm
2.4.62-1~deb12u1
fixed
bookworm (security)
2.4.62-1~deb12u2
fixed
sid
2.4.62-3
fixed
trixie
2.4.62-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
apache2
utopic
Fixed 2.4.10-1ubuntu1.1
released
trusty
Fixed 2.4.7-1ubuntu4.4
released
saucy
ignored
quantal
ignored
precise
Fixed 2.2.22-1ubuntu1.8
released
lucid
Fixed 2.2.14-5ubuntu8.15
released
References