Vulnerability CVE-2013-6438


Published: 2014-03-18

Description:
The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before 2.4.8 does not properly remove whitespace characters from CDATA sections, which allows remote attackers to cause a denial of service (daemon crash) via a crafted DAV WRITE request.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
Apache HTTP Server 2.4.7 dav_xml_get_cdata DoS
Apache
19.03.2014

Type:

CWE-20

(Improper Input Validation)

CVSS2 => (AV:N/AC:L/Au:N/C:N/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Partial
Affected software
Apache -> Http server 

 References:
http://advisories.mageia.org/MGASA-2014-0135.html
http://archives.neohapsis.com/archives/bugtraq/2014-10/0101.html
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10698
http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.html
http://marc.info/?l=bugtraq&m=141017844705317&w=2
http://marc.info/?l=bugtraq&m=141390017113542&w=2
http://seclists.org/fulldisclosure/2014/Dec/23
http://security.gentoo.org/glsa/glsa-201408-12.xml
http://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x/CHANGES
http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/dav/main/util.c
http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/dav/main/util.c?r1=1528718&r2=1556428&diff_format=h
http://www-01.ibm.com/support/docview.wss?uid=swg21669554
http://www-01.ibm.com/support/docview.wss?uid=swg21676091
http://www-01.ibm.com/support/docview.wss?uid=swg21676092
http://www.apache.org/dist/httpd/CHANGES_2.4.9
http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html
http://www.securityfocus.com/archive/1/534161/100/0/threaded
http://www.securityfocus.com/bid/66303
http://www.ubuntu.com/usn/USN-2152-1
http://www.vmware.com/security/advisories/VMSA-2014-0012.html
https://blogs.oracle.com/sunsecurity/entry/multiple_input_validation_vulnerabilities_in1
https://httpd.apache.org/security/vulnerabilities_24.html
https://puppet.com/security/cve/cve-2013-6438
https://support.apple.com/HT204659
https://support.apple.com/kb/HT6535

Copyright 2024, cxsecurity.com

 

Back to Top