MGASA-2013-0230

Source
https://advisories.mageia.org/MGASA-2013-0230.html
Import Source
https://advisories.mageia.org/MGASA-2013-0230.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2013-0230
Related
Published
2013-07-26T11:34:30Z
Modified
2013-07-26T11:34:24Z
Summary
Updated apache packages fix CVE-2013-1896
Details

Updated apache packages fix security vulnerability:

moddav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the moddav_svn module, but a certain href attribute in XML data refers to a non-DAV URI (CVE-2013-1896).

References
Credits

Affected packages

Mageia:2 / apache

Package

Name
apache
Purl
pkg:rpm/mageia/apache?distro=mageia-2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.2.25-1.mga2

Ecosystem specific

{
    "section": "core"
}