Summary: | <www-servers/apache-2.2.31: bypass of mod_headers rules via chunked requests (CVE-2013-5704) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Agostino Sarubbo <ago> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | minor | CC: | polynomial-c |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://bugzilla.redhat.com/show_bug.cgi?id=1082903 | ||
Whiteboard: | B4 [noglsa cve] | ||
Package list: | Runtime testing required: | --- |
Description
Agostino Sarubbo
2014-04-01 12:56:25 UTC
CVE-2013-5704 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-5704): The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a security issue in httpd as such." this should be already fixed in current versions in the tree: https://bugzilla.redhat.com/show_bug.cgi?id=1082903#c8 Current versions in tree are not vulnerable. GLSA Vote: No |