CVE-2013-1862

Modified
Published: 10 Jun 2013, 17:00
Last modified:06 Aug 2024, 15:20

Vulnerability Summary

Overall Risk (default)
medium
31/100
CVSS Score
5.1 MEDIUM
v2.0 (nvd)
EPSS Score
52.4% CRITICAL
52% probability +10.64%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

10 Jun 2013, 17:00
Published
Vulnerability first disclosed
06 Aug 2024, 15:20
Last Modified
Vulnerability information updated

Description

mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containing an escape sequence for a terminal emulator.

CVSS Metrics

  • v2.0MEDIUMScore: 5.1AV:N/AC:H/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 52.40% Percentile: 98%

Affected Systems

  • UnknownHTTP Server

    ≥ 2.0.0, < 2.0.65 | ≥ 2.2.0, < 2.2.25

  • canonicalubuntu_linux

    10.04 | 12.04 | 12.10 | 13.04

  • opensuseopensuse

    11.4 | 12.2 | 12.3

  • oraclehttp_server

    10.1.3.5.0 | 11.1.1.7.0 | 12.1.2.0 | 12.1.3.0

  • redhatenterprise_linux_desktop

    5.0 | 6.0

  • redhatenterprise_linux_eus

    5.9 | 6.4

  • redhatenterprise_linux_server

    5.0 | 6.0

  • redhatenterprise_linux_server_aus

    5.9 | 6.4

  • redhatenterprise_linux_workstation

    5.0 | 6.0

  • redhatjboss_enterprise_application_platform

    6.0.0 | 6.4.0

References (43)