Vulnerability Description
CRLF injection vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks by uploading a file with a multi-line name containing HTTP header sequences and a file extension, which leads to injection within a (1) "406 Not Acceptable" or (2) "300 Multiple Choices" HTTP response when the extension is omitted in a request for the file.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Http Server | >= 2.2.0, < 2.2.12 |
| Redhat | Enterprise Linux Desktop | 5.0 |
| Redhat | Enterprise Linux Server | 5.0 |
| Redhat | Enterprise Linux Workstation | 5.0 |
Related Weaknesses (CWE)
References
- http://lists.apple.com/archives/security-announce/2009/May/msg00002.htmlBroken LinkMailing ListThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0130.htmlThird Party Advisory
- http://secunia.com/advisories/29348Not ApplicableThird Party Advisory
- http://secunia.com/advisories/35074Not ApplicableThird Party Advisory
- http://security.gentoo.org/glsa/glsa-200803-19.xmlThird Party Advisory
- http://securityreason.com/securityalert/3575ExploitThird Party Advisory
- http://securitytracker.com/id?1019256Broken LinkThird Party AdvisoryVDB Entry
- http://support.apple.com/kb/HT3549Third Party Advisory
- http://www.mindedsecurity.com/MSA01150108.htmlBroken Link
- http://www.securityfocus.com/archive/1/486847/100/0/threadedThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/27409Third Party AdvisoryVDB Entry
- http://www.us-cert.gov/cas/techalerts/TA09-133A.htmlThird Party AdvisoryUS Government Resource
- http://www.vupen.com/english/advisories/2009/1297Permissions RequiredThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39893Third Party AdvisoryVDB Entry
- https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772
FAQ
What is CVE-2008-0456?
CVE-2008-0456 is a vulnerability with a CVSS score of 2.6 (LOW). CRLF injection vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x ...
How severe is CVE-2008-0456?
CVE-2008-0456 has been rated LOW with a CVSS base score of 2.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-0456?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Http Server, Redhat Enterprise Linux Desktop, Redhat Enterprise Linux Server, Redhat Enterprise Linux Workstation.