SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2013-1896

mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for…

MEDIUM 4.3EPSS 29.5%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 29.5%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.

Description

mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.

CVSS 2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
EPSS
29.48% probability · 98th percentile
CISA KEV
Not listed
Affected
apache/http server · redhat/jboss enterprise application platform · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux workstation · canonical/ubuntu linux · opensuse/opensuse
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.