CVE-2013-1896

Modified
Published: 10 Jul 2013, 20:00
Last modified:06 Aug 2024, 15:20

Vulnerability Summary

Overall Risk (default)
medium
36/100
CVSS Score
4.3 MEDIUM
v2.0 (nvd)
EPSS Score
43.96% HIGH
44% probability +5.41%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

10 Jul 2013, 20:00
Published
Vulnerability first disclosed
06 Aug 2024, 15:20
Last Modified
Vulnerability information updated

Description

mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.

CVSS Metrics

  • v2.0MEDIUMScore: 4.3AV:N/AC:M/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 43.96% Percentile: 98%

Affected Systems

  • UnknownHTTP Server

    ≥ 2.2.0, < 2.2.25 | ≥ 2.4.1, < 2.4.6

  • canonicalubuntu_linux

    10.04 | 12.04 | 12.10 | 13.04

  • opensuseopensuse

    11.4 | 12.2 | 12.3

  • redhatenterprise_linux_desktop

    5.0 | 6.0

  • redhatenterprise_linux_eus

    5.9 | 6.4

  • redhatenterprise_linux_server

    5.0 | 6.0

  • redhatenterprise_linux_server_aus

    5.9 | 6.4

  • redhatenterprise_linux_workstation

    5.0 | 6.0

  • redhatjboss_enterprise_application_platform

    6.0.0 | 6.4.0

References (39)