CVE-2013-1896

Description

mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
38.555

Associated Vulnerability

VulnerabilityOS Platform
Update Apache to version 2.4.6Windows
Update Apache to version 2.2.24Windows
Multiple vulnerabilities are fixed in Apache 2.2.2Windows
Vulnerabilities CVE-2013-1896 are fixed in Apache 2.4.6Windows
Update Apache to version 2.4.6 (For Linux)Linux
Update Apache to version 2.2.24 (For Linux)Linux
Apache HTTP Server MERGE Request Denial of Service Vulnerability For Cisco Unified Computing SystemNCM
CVE-2013-1896NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1706036Security Update for Cisco Unified Computing System 3.2(1d)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234