CVE-2013-5704

Description

The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass RequestHeader unset directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states this is not a security issue in httpd as such.

Risk Information

Base Score
9.1
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Score
Exploitation Probability
76.146

Associated Vulnerability

VulnerabilityOS Platform
Update Apache to version 2.4.12Windows
Update Apache to version 2.2.27Windows
Vulnerabilities CVE-2013-5704,CVE-2014-0118,CVE-2014-0226,CVE-2014-0231 are fixed in Apache 2.2.29Windows
Vulnerabilities CVE-2013-5704 are fixed in Apache 2.4.12Windows
Multiple vulnerabilities are fixed in IBM WebSphere 8.5.5.4Windows
Multiple vulnerabilities are fixed in IBM WebSphere 8.0.0.10Windows
Multiple vulnerabilities are fixed in IBM WebSphere 7.0.0.35Windows
Multiple vulnerabilities are affected in Oracle HTTP Server 5.0Windows
Apache HTTP server (USN-2523-1) apache2.2-bin_2.4.7-1ubuntu4.5_i386.debLinux
Apache HTTP server (USN-2523-1) apache2.2-bin_2.4.7-1ubuntu4.5_amd64.debLinux
Apache HTTP server (USN-3038-1) apache2.2-bin_2.4.10-1ubuntu1.1~ubuntu14.04.2_i386.debLinux
Apache HTTP server (USN-3038-1) apache2.2-bin_2.4.10-1ubuntu1.1~ubuntu14.04.2_amd64.debLinux
Apache2 2.4.7-1ubuntu4.15 for Ubuntu 14.04 LTS (x64) apache2_2.4.10-1ubuntu1.1~ubuntu14.04.2_amd64.debLinux
Apache2 2.4.7-1ubuntu4.15 for Ubuntu 14.04 LTS apache2_2.4.10-1ubuntu1.1~ubuntu14.04.2_i386.debLinux
Apache HTTP server (USN-3340-1) apache2-bin_2.4.10-1ubuntu1.1~ubuntu14.04.2_amd64.debLinux
Apache HTTP server (USN-3425-1) apache2-bin_2.4.10-1ubuntu1.1~ubuntu14.04.2_amd64.debLinux
Apache HTTP server (USN-3425-1) apache2-bin_2.4.10-1ubuntu1.1~ubuntu14.04.2_i386.debLinux
Apache HTTP server (USN-3370-1) apache2-bin_2.4.10-1ubuntu1.1~ubuntu14.04.2_i386.debLinux
Apache HTTP server (USN-3370-1) apache2-bin_2.4.10-1ubuntu1.1~ubuntu14.04.2_amd64.debLinux
Httpd24-httpd update (ELSA-2014-1972) httpd24-httpd-2.4.6-22.0.1.el6.x86_64.rpmLinux
Httpd24-httpd-devel update (ELSA-2014-1972) httpd24-httpd-devel-2.4.6-22.0.1.el6.x86_64.rpmLinux
Httpd24-httpd-tools update (ELSA-2014-1972) httpd24-httpd-tools-2.4.6-22.0.1.el6.x86_64.rpmLinux
Httpd24-mod_ldap update (ELSA-2014-1972) httpd24-mod_ldap-2.4.6-22.0.1.el6.x86_64.rpmLinux
Httpd24-mod_proxy_html update (ELSA-2014-1972) httpd24-mod_proxy_html-2.4.6-22.0.1.el6.x86_64.rpmLinux
Httpd24-mod_session update (ELSA-2014-1972) httpd24-mod_session-2.4.6-22.0.1.el6.x86_64.rpmLinux
Httpd24-mod_ssl update (ELSA-2014-1972) httpd24-mod_ssl-2.4.6-22.0.1.el6.x86_64.rpmLinux
Httpd24-httpd-manual update (ELSA-2014-1972) httpd24-httpd-manual-2.4.6-22.0.1.el6.noarch.rpmLinux
Update Apache to version 2.4.12 (For Linux)Linux
Update Apache to version 2.2.27 (For Linux)Linux
CVE-2013-5704NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234