← All CVEs

CVE-2013-1896

medium · 4.3

mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.

4.3
CVSS
29.5%
EPSS (exploit prob.)
98th
EPSS percentile
2013-07-10
Published

AV:N/AC:M/Au:N/C:N/I:N/A:P

Affected products

VendorProductAffected versions
apachehttp_server>= 2.2.0, < 2.2.25
apachehttp_server>= 2.4.1, < 2.4.6
redhatjboss_enterprise_application_platform6.0.0
redhatjboss_enterprise_application_platform6.4.0
redhatenterprise_linux5.0
redhatenterprise_linux6.0
redhatenterprise_linux_desktop5.0
redhatenterprise_linux_desktop6.0
redhatenterprise_linux_eus5.9
redhatenterprise_linux_eus6.4
redhatenterprise_linux_server5.0
redhatenterprise_linux_server6.0
redhatenterprise_linux_server_aus5.9
redhatenterprise_linux_server_aus6.4
redhatenterprise_linux_workstation5.0
redhatenterprise_linux_workstation6.0
canonicalubuntu_linux10.04
canonicalubuntu_linux12.04
canonicalubuntu_linux12.10
canonicalubuntu_linux13.04
opensuseopensuse11.4
opensuseopensuse12.2
opensuseopensuse12.3

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2013-1896