MGASA-2013-0230
Dashboard / Vulnerabilities / MGASA-2013-0230
Summary: Updated apache packages fix CVE-2013-1896
Details: Updated apache packages fix security vulnerability: mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI (CVE-2013-1896).
References: https://advisories.mageia.org/MGASA-2013-0230.html, http://httpd.apache.org/security/vulnerabilities_22.html, http://www.apache.org/dist/httpd/CHANGES_2.2.25, http://www.mandriva.com/en/support/security/advisories/mbs1/MDVSA-2013:193/, https://bugs.mageia.org/show_bug.cgi?id=10756
Affected packages
Package
Name: apache
Purl: pkg:rpm/mageia/apache?arch=source&distro=mageia-2
Affected ranges
Type: ECOSYSTEM
Events:
