Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:11148
HistoryJan 15, 2019 - 8:57 a.m.

Denial Of Service (DoS)

2019-01-1508:57:40
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

EPSS

0.927

Percentile

99.0%

httpd is vulnerable to denial of service (DoS) attacks. The vulnerability exists as mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.

References