SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2013-1862

mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containing…

MEDIUM 5.1EPSS 24.9%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 24.9%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.

Description

mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containing an escape sequence for a terminal emulator.

CVSS 2.0
5.1 MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
EPSS
24.89% probability · 98th percentile
CISA KEV
Not listed
Affected
apache/http server · redhat/jboss enterprise application platform · oracle/http server · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux workstation · canonical/ubuntu linux · opensuse/opensuse
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.