UBUNTU-CVE-2013-5704
Dashboard / Vulnerabilities / UBUNTU-CVE-2013-5704
UBUNTU-CVE-2013-5704
Summary:
Details: The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a security issue in httpd as such."
References: https://ubuntu.com/security/CVE-2013-5704, http://martin.swende.se/blog/HTTPChunked.html, http://marc.info/?l=apache-httpd-dev&m=139636309822854&w=2, http://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x/CHANGES, https://ubuntu.com/security/notices/USN-2523-1, https://www.cve.org/CVERecord?id=CVE-2013-5704
Affected packages
Package
Name: apache2
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
