5

CVE-2013-5704

Exploit

The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding.  NOTE: the vendor states "this is not a security issue in httpd as such."

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ApacheHTTP Server Version2.2.0
ApacheHTTP Server Version2.2.2
ApacheHTTP Server Version2.2.3
ApacheHTTP Server Version2.2.4
ApacheHTTP Server Version2.2.5
ApacheHTTP Server Version2.2.6
ApacheHTTP Server Version2.2.8
ApacheHTTP Server Version2.2.9
ApacheHTTP Server Version2.2.10
ApacheHTTP Server Version2.2.11
ApacheHTTP Server Version2.2.12
ApacheHTTP Server Version2.2.13
ApacheHTTP Server Version2.2.14
ApacheHTTP Server Version2.2.15
ApacheHTTP Server Version2.2.16
ApacheHTTP Server Version2.2.17
ApacheHTTP Server Version2.2.18
ApacheHTTP Server Version2.2.19
ApacheHTTP Server Version2.2.20
ApacheHTTP Server Version2.2.21
ApacheHTTP Server Version2.2.22
ApacheHTTP Server Version2.2.23
ApacheHTTP Server Version2.2.24
ApacheHTTP Server Version2.2.25
ApacheHTTP Server Version2.2.26
ApacheHTTP Server Version2.2.27
ApacheHTTP Server Version2.4.1
ApacheHTTP Server Version2.4.2
ApacheHTTP Server Version2.4.3
ApacheHTTP Server Version2.4.4
ApacheHTTP Server Version2.4.6
ApacheHTTP Server Version2.4.7
ApacheHTTP Server Version2.4.9
ApacheHTTP Server Version2.4.10
RedhatEnterprise Linux Eus Version7.3
RedhatEnterprise Linux Eus Version7.4
RedhatEnterprise Linux Eus Version7.5
RedhatEnterprise Linux Eus Version7.6
RedhatEnterprise Linux Eus Version7.7
RedhatJboss Enterprise Web Server Version3.0.0
   RedhatEnterprise Linux Version6.0
   RedhatEnterprise Linux Version7.0
RedhatJboss Enterprise Web Server Version2.0.0
   RedhatEnterprise Linux Version5.0
   RedhatEnterprise Linux Version6.0
   RedhatEnterprise Linux Version7.0
OracleHTTP Server Version10.1.3.5.0
OracleHTTP Server Version11.1.1.7.0
OracleHTTP Server Version12.1.2.0
OracleHTTP Server Version12.1.3.0
OracleLinux Version6 Update-
OracleSolaris Version11.2
ApplemacOS X Version < 10.10.4
ApplemacOS X Server Version < 5.0.3
CanonicalUbuntu Linux Version10.04 SwEdition-
CanonicalUbuntu Linux Version12.04 SwEdition-
CanonicalUbuntu Linux Version14.04 SwEditionesm
CanonicalUbuntu Linux Version14.10
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 75.57% 0.989
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
http://marc.info/?l=bugtraq&m=143403519711434&w=2
Third Party Advisory
Mailing List
Issue Tracking
http://marc.info/?l=bugtraq&m=144493176821532&w=2
Third Party Advisory
Mailing List
Issue Tracking
http://martin.swende.se/blog/HTTPChunked.html
Third Party Advisory
Exploit
Broken Link
http://rhn.redhat.com/errata/RHSA-2015-2661.html
Third Party Advisory
Broken Link
http://www.securityfocus.com/bid/66550
Third Party Advisory
VDB Entry