FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2013-1896

This CVE name corresponds to:

Entered Topic
2013-07-20 apache24 -- several vulnerabilities
2013-07-05 apache22 -- several vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2013-1896
Phase Assigned(20130219)

Description

mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.

References

Source Reference
CONFIRM http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/dav/main/mod_dav.c?r1=1482522&r2=1485668&diff_format=h
CONFIRM http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/dav/main/mod_dav.c?view=log
CONFIRM http://www.apache.org/dist/httpd/Announcement2.2.html
CONFIRM http://www-01.ibm.com/support/docview.wss?uid=swg21644047
CONFIRM http://support.apple.com/kb/HT6150
CISCO 20130822 Apache HTTP Server MERGE Request Denial of Service Vulnerability
HP HPSBUX02927
HP SSRT101288
REDHAT RHSA-2013:1156
REDHAT RHSA-2013:1207
REDHAT RHSA-2013:1208
REDHAT RHSA-2013:1209
SUSE openSUSE-SU-2013:1337
SUSE openSUSE-SU-2013:1340
SUSE openSUSE-SU-2013:1341
UBUNTU USN-1903-1
OVAL oval:org.mitre.oval:def:18835
OVAL oval:org.mitre.oval:def:19747
SECUNIA 55032