LWN.net Logo

Advertisement

GStreamer, Embedded Linux, Android, VoD, Smooth Streaming, DRM, RTSP, HEVC, PulseAudio, OpenGL. Register now to attend.

Advertise here

apache: denial of service

Package(s):apache2 CVE #(s):CVE-2013-1896
Created:July 15, 2013 Updated:August 14, 2013
Description: From the CVE entry:

mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.

Alerts:
Ubuntu USN-1903-1 2013-07-15
Mandriva MDVSA-2013:193 2013-07-11
Slackware SSA:2013-218-02 2013-08-06
Fedora FEDORA-2013-13994 2013-08-09
Red Hat RHSA-2013:1156-01 2013-08-13
CentOS CESA-2013:1156 2013-08-13
CentOS CESA-2013:1156 2013-08-13
openSUSE openSUSE-SU-2013:1337-1 2013-08-14
openSUSE openSUSE-SU-2013:1340-1 2013-08-14
openSUSE openSUSE-SU-2013:1341-1 2013-08-14
Oracle ELSA-2013-1156 2013-08-13
Oracle ELSA-2013-1156 2013-08-13
Scientific Linux SLSA-2013:1156-1 2013-08-13
Fedora FEDORA-2013-13922 2013-08-16
Gentoo 201309-12 2013-09-23

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds