MGASA-2013-0174
Dashboard / Vulnerabilities / MGASA-2013-0174
Summary: Updated apache packages fix security vulnerabilities
Details: It was found that mod_rewrite did not filter terminal escape sequences from its log file. If mod_rewrite was configured with the RewriteLog directive, a remote attacker could use specially-crafted HTTP requests to inject terminal escape sequences into the mod_rewrite log file. If a victim viewed the log file with a terminal emulator, it could result in arbitrary command execution with the privileges of that user (CVE-2013-1862). A buffer overflow when reading digest password file with very long lines in htdigest (PR54893)
References: https://advisories.mageia.org/MGASA-2013-0174.html, https://bugs.mageia.org/show_bug.cgi?id=10097, https://issues.apache.org/bugzilla/show_bug.cgi?id=54893, https://rhn.redhat.com/errata/RHSA-2013-0815.html
Affected packages
Package
Name: apache
Purl: pkg:rpm/mageia/apache?arch=source&distro=mageia-2
Affected ranges
Type: ECOSYSTEM
Events:
