From ${URL} : Martin Holst Swende discovered a flaw in the way mod_headers handled chunked requests. A remote attacker could use this flaw to bypass intended mod_headers restrictions, allowing them to send requests to applications that include headers that should have been removed by mod_headers. Discussion and a possible patch is available from the following thread: http://marc.info/?t=138219209900002&r=1&w=2 References: http://martin.swende.se/blog/HTTPChunked.html @maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
CVE-2013-5704 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-5704): The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a security issue in httpd as such."
this should be already fixed in current versions in the tree: https://bugzilla.redhat.com/show_bug.cgi?id=1082903#c8
Current versions in tree are not vulnerable. GLSA Vote: No