Vulnerability Description
The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before 2.4.8 does not properly remove whitespace characters from CDATA sections, which allows remote attackers to cause a denial of service (daemon crash) via a crafted DAV WRITE request.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Http Server | >= 2.2.0, < 2.2.27 |
| Oracle | Http Server | 10.1.3.5.0 |
| Canonical | Ubuntu Linux | 10.04 |
References
- http://advisories.mageia.org/MGASA-2014-0135.htmlThird Party Advisory
- http://archives.neohapsis.com/archives/bugtraq/2014-10/0101.htmlBroken Link
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10698Third Party Advisory
- http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.htmlBroken LinkMailing List
- http://marc.info/?l=bugtraq&m=141017844705317&w=2Issue TrackingMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=141390017113542&w=2Issue TrackingMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2014/Dec/23Mailing ListThird Party Advisory
- http://secunia.com/advisories/58230Not Applicable
- http://secunia.com/advisories/59315Not Applicable
- http://secunia.com/advisories/59345Not Applicable
- http://secunia.com/advisories/60536Not Applicable
- http://security.gentoo.org/glsa/glsa-201408-12.xmlThird Party Advisory
- http://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x/CHANGESVendor Advisory
- http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/dav/main/util.cVendor Advisory
- http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/dav/main/util.c?r1=152871PatchVendor Advisory
FAQ
What is CVE-2013-6438?
CVE-2013-6438 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before 2.4.8 does not properly remove whitespace characters from CDATA sections, which allows remote attac...
How severe is CVE-2013-6438?
CVE-2013-6438 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-6438?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Http Server, Oracle Http Server, Canonical Ubuntu Linux.