FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2013-5704

This CVE name corresponds to:

Entered Topic
2015-01-31 apache24 -- several vulnerabilities
2014-07-24 apache22 -- several vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2013-5704
Phase Assigned(20130905)

Description

The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a security issue in httpd as such."

References

Source Reference
MLIST [dev] 20140401 CVE-2013-5704, mod_headers and chunked trailer fields
MISC http://martin.swende.se/blog/HTTPChunked.html
CONFIRM http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/proxy/mod_proxy_http.c
CONFIRM http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/proxy/mod_proxy_http.c?r1=1610674&r2=1610814&diff_format=h
CONFIRM http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
CONFIRM https://support.apple.com/HT204659
CONFIRM http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html
CONFIRM https://support.apple.com/HT205219
CONFIRM http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html
APPLE APPLE-SA-2015-04-08-2
APPLE APPLE-SA-2015-09-16-4
REDHAT RHSA-2015:0325
UBUNTU USN-2523-1
BID 66550