MEDIUM · 5.1

CVE-2013-1862

mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execu...

Vulnerability Description

mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containing an escape sequence for a terminal emulator.

CVSS Score

5.1

MEDIUM

AV:N/AC:H/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
ApacheHttp Server>= 2.0.0, < 2.0.65
RedhatJboss Enterprise Application Platform6.0.0
RedhatEnterprise Linux5.0
OracleHttp Server10.1.3.5.0
RedhatEnterprise Linux Desktop5.0
RedhatEnterprise Linux Eus5.9
RedhatEnterprise Linux Server5.0
RedhatEnterprise Linux Server Aus5.9
RedhatEnterprise Linux Workstation5.0
CanonicalUbuntu Linux10.04
OpensuseOpensuse11.4

References

FAQ

What is CVE-2013-1862?

CVE-2013-1862 is a vulnerability with a CVSS score of 5.1 (MEDIUM). mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execu...

How severe is CVE-2013-1862?

CVE-2013-1862 has been rated MEDIUM with a CVSS base score of 5.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-1862?

Check the references section above for vendor advisories and patch information. Affected products include: Apache Http Server, Redhat Jboss Enterprise Application Platform, Redhat Enterprise Linux, Oracle Http Server, Redhat Enterprise Linux Desktop.