Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2013-5704


The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a security issue in httpd as such."


Published

2014-04-15T10:55:11.150

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 5.0 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache http_server 2.2.0 Yes
Application apache http_server 2.2.2 Yes
Application apache http_server 2.2.3 Yes
Application apache http_server 2.2.4 Yes
Application apache http_server 2.2.5 Yes
Application apache http_server 2.2.6 Yes
Application apache http_server 2.2.8 Yes
Application apache http_server 2.2.9 Yes
Application apache http_server 2.2.10 Yes
Application apache http_server 2.2.11 Yes
Application apache http_server 2.2.12 Yes
Application apache http_server 2.2.13 Yes
Application apache http_server 2.2.14 Yes
Application apache http_server 2.2.15 Yes
Application apache http_server 2.2.16 Yes
Application apache http_server 2.2.17 Yes
Application apache http_server 2.2.18 Yes
Application apache http_server 2.2.19 Yes
Application apache http_server 2.2.20 Yes
Application apache http_server 2.2.21 Yes
Application apache http_server 2.2.22 Yes
Application apache http_server 2.2.23 Yes
Application apache http_server 2.2.24 Yes
Application apache http_server 2.2.25 Yes
Application apache http_server 2.2.26 Yes
Application apache http_server 2.2.27 Yes
Application apache http_server 2.4.1 Yes
Application apache http_server 2.4.2 Yes
Application apache http_server 2.4.3 Yes
Application apache http_server 2.4.4 Yes
Application apache http_server 2.4.6 Yes
Application apache http_server 2.4.7 Yes
Application apache http_server 2.4.9 Yes
Application apache http_server 2.4.10 Yes
Operating System redhat enterprise_linux_desktop 6.0 Yes
Operating System redhat enterprise_linux_desktop 7.0 Yes
Operating System redhat enterprise_linux_eus 7.3 Yes
Operating System redhat enterprise_linux_eus 7.4 Yes
Operating System redhat enterprise_linux_eus 7.5 Yes
Operating System redhat enterprise_linux_eus 7.6 Yes
Operating System redhat enterprise_linux_eus 7.7 Yes
Operating System redhat enterprise_linux_server 6.0 Yes
Operating System redhat enterprise_linux_server 7.0 Yes
Operating System redhat enterprise_linux_server_aus 7.3 Yes
Operating System redhat enterprise_linux_server_aus 7.4 Yes
Operating System redhat enterprise_linux_server_aus 7.6 Yes
Operating System redhat enterprise_linux_server_aus 7.7 Yes
Operating System redhat enterprise_linux_server_tus 7.3 Yes
Operating System redhat enterprise_linux_server_tus 7.6 Yes
Operating System redhat enterprise_linux_server_tus 7.7 Yes
Operating System redhat enterprise_linux_workstation 6.0 Yes
Operating System redhat enterprise_linux_workstation 7.0 Yes
Application redhat jboss_enterprise_web_server 3.0.0 Yes
Operating System redhat enterprise_linux 6.0 No
Operating System redhat enterprise_linux 7.0 No
Application redhat jboss_enterprise_web_server 2.0.0 Yes
Operating System redhat enterprise_linux 5.0 No
Operating System redhat enterprise_linux 6.0 No
Operating System redhat enterprise_linux 7.0 No
Application oracle enterprise_manager_ops_center < 12.1.4 Yes
Application oracle enterprise_manager_ops_center 12.1.4 Yes
Application oracle enterprise_manager_ops_center 12.2.0 Yes
Application oracle enterprise_manager_ops_center 12.2.1 Yes
Application oracle enterprise_manager_ops_center 12.3.0 Yes
Application oracle http_server 10.1.3.5.0 Yes
Application oracle http_server 11.1.1.7.0 Yes
Application oracle http_server 12.1.2.0 Yes
Application oracle http_server 12.1.3.0 Yes
Operating System oracle linux 6 Yes
Operating System oracle solaris 11.2 Yes
Operating System apple mac_os_x < 10.10.4 Yes
Operating System apple mac_os_x_server < 5.0.3 Yes
Operating System canonical ubuntu_linux 10.04 Yes
Operating System canonical ubuntu_linux 12.04 Yes
Operating System canonical ubuntu_linux 14.04 Yes
Operating System canonical ubuntu_linux 14.10 Yes

References