FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2013-1862

This CVE name corresponds to:

Entered Topic
2013-07-05 apache22 -- several vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2013-1862
Phase Assigned(20130219)

Description

mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containing an escape sequence for a terminal emulator.

References

Source Reference
CONFIRM http://people.apache.org/~jorton/mod_rewrite-CVE-2013-1862.patch
CONFIRM http://svn.apache.org/viewvc?view=revision&revision=r1469311
CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=953729
CONFIRM http://www-01.ibm.com/support/docview.wss?uid=swg21644047
CONFIRM http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
CONFIRM http://support.apple.com/kb/HT6150
CISCO 20130822 Apache HTTP Server mod_rewrite Log File Manipulation Vulnerability
HP HPSBUX02927
HP SSRT101288
MANDRIVA MDVSA-2013:174
REDHAT RHSA-2013:0815
REDHAT RHSA-2013:1207
REDHAT RHSA-2013:1208
REDHAT RHSA-2013:1209
SUSE openSUSE-SU-2013:1337
SUSE openSUSE-SU-2013:1340
SUSE openSUSE-SU-2013:1341
UBUNTU USN-1903-1
BID 64758
OVAL oval:org.mitre.oval:def:18790
OVAL oval:org.mitre.oval:def:19534
SECUNIA 55032