CVE-2013-1862
mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containing…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 24.9%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containing an escape sequence for a terminal emulator.
- CVSS 2.0
- 5.1 MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
- EPSS
- 24.89% probability · 98th percentile
- CISA KEV
- Not listed
- Affected
- apache/http server · redhat/jboss enterprise application platform · oracle/http server · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux workstation · canonical/ubuntu linux · opensuse/opensuse
- Source
- secalert@redhat.com
References
- http://lists.opensuse.org/opensuse-updates/2013-08/msg00026.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-08/msg00029.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-08/msg00030.htmlMailing List, Third Party Advisory
- http://people.apache.org/~jorton/mod_rewrite-CVE-2013-1862.patchPatch, Vendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0815.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1207.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1208.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1209.htmlThird Party Advisory
- http://secunia.com/advisories/55032Not Applicable
- http://support.apple.com/kb/HT6150Third Party Advisory
- http://svn.apache.org/viewvc?view=revision&revision=r1469311Patch, Vendor Advisory
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-1862Broken Link
- http://www-01.ibm.com/support/docview.wss?uid=swg21644047Third Party Advisory
- http://www.fujitsu.com/global/support/software/security/products-f/interstage-201303e.htmlThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:174Broken Link
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.htmlThird Party Advisory
- http://www.securityfocus.com/bid/59826Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/64758Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1903-1Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=953729Issue Tracking, Third Party Advisory
- https://h20566.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?spf_p.tpst=kbDocDisplay&spf_p.prp_kbDocDisplay=wsrp-navigationalState%3DdocId%253Demr_na-c03922406-1%257CdocLocale%253D%257CcalledBy%253D&javax.portlet.begCacheTok=com.vignette.cachetoken&javax.portlet.endCacheTok=com.vignette.cachetokenBroken Link
- https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/r05b5357d1f6bd106f41541ee7d87aafe3f5ea4dc3e9bde5ce09baff8%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.