Lucene search

K
ubuntucveUbuntu.comUB:CVE-2013-5704
HistoryApr 15, 2014 - 12:00 a.m.

CVE-2013-5704

2014-04-1500:00:00
ubuntu.com
ubuntu.com
28

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

0.467 Medium

EPSS

Percentile

97.5%

The mod_headers module in the Apache HTTP Server 2.2.22 allows remote
attackers to bypass โ€œRequestHeader unsetโ€ directives by placing a header in
the trailer portion of data sent with chunked transfer coding. NOTE: the
vendor states โ€œthis is not a security issue in httpd as such.โ€

Bugs

Notes

Author Note
mdeslaur check for r1610814, r1610686, r1610707
OSVersionArchitecturePackageVersionFilename
ubuntu10.04noarchapache2<ย 2.2.14-5ubuntu8.15UNKNOWN
ubuntu12.04noarchapache2<ย 2.2.22-1ubuntu1.8UNKNOWN
ubuntu14.04noarchapache2<ย 2.4.7-1ubuntu4.4UNKNOWN
ubuntu14.10noarchapache2<ย 2.4.10-1ubuntu1.1UNKNOWN

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

0.467 Medium

EPSS

Percentile

97.5%