CVE-2013-5704
Published Apr 15, 2014
Last updated a year ago
Overview
- Description
- The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a security issue in httpd as such."
- Source
- cve@mitre.org
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- NVD-CWE-noinfo
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:apache:http_server:2.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "67AD11FB-529C-404E-A13B-284F145322B8" }, { "criteria": "cpe:2.3:a:apache:http_server:2.2.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CCBBB7FE-35FC-4515-8393-5145339FCE4D" }, { "criteria": "cpe:2.3:a:apache:http_server:2.2.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F519633F-AB68-495A-B85E-FD41F9F752CA" }, { "criteria": "cpe:2.3:a:apache:http_server:2.2.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A894BED6-C97D-4DA4-A13D-9CB2B3306BC5" }, { "criteria": "cpe:2.3:a:apache:http_server:2.2.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "49A81C75-4C54-43FE-9317-E15EDFEC06B6" }, { "criteria": "cpe:2.3:a:apache:http_server:2.2.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "34A847D1-5AD5-4EFD-B165-7602AFC1E656" }, { "criteria": "cpe:2.3:a:apache:http_server:2.2.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9AF3A0F5-4E5C-4278-9927-1F94F25CCAFC" }, { "criteria": "cpe:2.3:a:apache:http_server:2.2.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AB63EBE5-CF14-491E-ABA5-67116DFE3E5B" }, { "criteria": "cpe:2.3:a:apache:http_server:2.2.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8C2A33DE-F55F-4FD8-BB00-9C1E006CA65C" }, { "criteria": "cpe:2.3:a:apache:http_server:2.2.11:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B1CF6394-95D9-42AF-A442-385EFF9CEFE1" }, { "criteria": "cpe:2.3:a:apache:http_server:2.2.12:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "02B629FB-88C8-4E85-A137-28770F1E524E" }, { "criteria": "cpe:2.3:a:apache:http_server:2.2.13:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "03550EF0-DF89-42FE-BF0E-994514EBD947" }, { "criteria": "cpe:2.3:a:apache:http_server:2.2.14:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4886CCAB-6D4E-45C7-B177-2E8DBEA15531" }, { "criteria": "cpe:2.3:a:apache:http_server:2.2.15:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C35631AC-7C35-4F6A-A95A-3B080E5210ED" }, { "criteria": "cpe:2.3:a:apache:http_server:2.2.16:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6CED2BA6-BE5E-4EF1-88EB-0DADD23D2EEF" }, { "criteria": "cpe:2.3:a:apache:http_server:2.2.17:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A71F4154-AD20-4EEA-9E2E-D3385C357DA5" }, { "criteria": "cpe:2.3:a:apache:http_server:2.2.18:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B0B8C9DB-401E-42B3-BAED-D09A96DE9A90" }, { "criteria": "cpe:2.3:a:apache:http_server:2.2.19:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "062C20A0-05A0-4164-8330-DF6ADFE607F4" }, { "criteria": "cpe:2.3:a:apache:http_server:2.2.20:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D345BA35-93BB-406F-B5DC-86E49FB29C22" }, { "criteria": "cpe:2.3:a:apache:http_server:2.2.21:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7ED4892F-C829-4BEA-AB82-6A78F6F2426D" }, { "criteria": "cpe:2.3:a:apache:http_server:2.2.22:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "00128AAD-E746-4DCD-8676-1381E5232220" }, { "criteria": "cpe:2.3:a:apache:http_server:2.2.23:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FE0D7ABB-DE11-40D6-8AAF-C626DD7E3914" }, { "criteria": "cpe:2.3:a:apache:http_server:2.2.24:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5252544F-7BDD-42EE-856E-B351B4B6D381" }, { "criteria": "cpe:2.3:a:apache:http_server:2.2.25:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "58375DE5-F7EC-400D-84A2-CD70B72C4F63" }, { "criteria": "cpe:2.3:a:apache:http_server:2.2.26:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "15233815-C037-41BB-A447-A078F83A93F6" }, { "criteria": "cpe:2.3:a:apache:http_server:2.2.27:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5444C583-CF83-4ECD-8DF8-66D8C1FCF096" }, { "criteria": "cpe:2.3:a:apache:http_server:2.4.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6FCD3C8C-9BF8-4F30-981A-593EEAEB9EDD" }, { "criteria": "cpe:2.3:a:apache:http_server:2.4.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "046487A3-752B-4D0F-8984-96486B828EAB" }, { "criteria": "cpe:2.3:a:apache:http_server:2.4.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "89D2E052-51CD-4B57-A8B8-FAE51988D654" }, { "criteria": "cpe:2.3:a:apache:http_server:2.4.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EAA27058-BACF-4F94-8E3C-7D38EC302EC1" }, { "criteria": "cpe:2.3:a:apache:http_server:2.4.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8FEAB0DF-04A9-4F99-8666-0BADC5D642B8" }, { "criteria": "cpe:2.3:a:apache:http_server:2.4.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E7D924D1-8A36-4C43-9E56-52814F9A6350" }, { "criteria": "cpe:2.3:a:apache:http_server:2.4.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "39CDFECC-E26D-47E0-976F-6629040B3764" }, { "criteria": "cpe:2.3:a:apache:http_server:2.4.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E3ECBCB1-0675-41F5-857B-438F36925F63" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EE249E1B-A1FD-4E08-AA71-A0E1F10FFE97" }, { "criteria": "cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "33C068A4-3780-4EAB-A937-6082DF847564" }, { "criteria": "cpe:2.3:o:redhat:enterprise_linux_eus:7.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "807C024A-F8E8-4B48-A349-4C68CD252CA1" }, { "criteria": "cpe:2.3:o:redhat:enterprise_linux_eus:7.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F96E3779-F56A-45FF-BB3D-4980527D721E" }, { "criteria": "cpe:2.3:o:redhat:enterprise_linux_eus:7.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0CF73560-2F5B-4723-A8A1-9AADBB3ADA00" }, { "criteria": "cpe:2.3:o:redhat:enterprise_linux_eus:7.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5BF3C7A5-9117-42C7-BEA1-4AA378A582EF" }, { "criteria": "cpe:2.3:o:redhat:enterprise_linux_eus:7.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "83737173-E12E-4641-BC49-0BD84A6B29D0" }, { "criteria": "cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9BBCD86A-E6C7-4444-9D74-F861084090F0" }, { "criteria": "cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "51EF4996-72F4-4FA4-814F-F5991E7A8318" }, { "criteria": "cpe:2.3:o:redhat:enterprise_linux_server_aus:7.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "98381E61-F082-4302-B51F-5648884F998B" }, { "criteria": "cpe:2.3:o:redhat:enterprise_linux_server_aus:7.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D99A687E-EAE6-417E-A88E-D0082BC194CD" }, { "criteria": "cpe:2.3:o:redhat:enterprise_linux_server_aus:7.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B353CE99-D57C-465B-AAB0-73EF581127D1" }, { "criteria": "cpe:2.3:o:redhat:enterprise_linux_server_aus:7.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7431ABC1-9252-419E-8CC1-311B41360078" }, { "criteria": "cpe:2.3:o:redhat:enterprise_linux_server_tus:7.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "24C0F4E1-C52C-41E0-9F14-F83ADD5CC7ED" }, { "criteria": "cpe:2.3:o:redhat:enterprise_linux_server_tus:7.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B76AA310-FEC7-497F-AF04-C3EC1E76C4CC" }, { "criteria": "cpe:2.3:o:redhat:enterprise_linux_server_tus:7.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "17F256A9-D3B9-4C72-B013-4EFD878BFEA8" }, { "criteria": "cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E5ED5807-55B7-47C5-97A6-03233F4FBC3A" }, { "criteria": "cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "825ECE2D-E232-46E0-A047-074B34DB1E97" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:redhat:jboss_enterprise_web_server:3.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8E2F2F98-DB90-43F6-8F28-3656207B6188" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "2F6AB192-9D7D-4A9A-8995-E53A9DE9EAFC" }, { "criteria": "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "142AD0DD-4CF3-4D74-9442-459CE3347E3A" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:redhat:jboss_enterprise_web_server:2.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "681173DF-537E-4A64-8FC7-75F439CCAD0D" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:redhat:enterprise_linux:5.0:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "1D8B549B-E57B-4DFE-8A13-CAB06B5356B3" }, { "criteria": "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "2F6AB192-9D7D-4A9A-8995-E53A9DE9EAFC" }, { "criteria": "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "142AD0DD-4CF3-4D74-9442-459CE3347E3A" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:oracle:enterprise_manager_ops_center:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A70BB445-EF2B-4C9D-8502-FDD6A19F8C30", "versionEndExcluding": "12.1.4" }, { "criteria": "cpe:2.3:a:oracle:enterprise_manager_ops_center:12.1.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BA2CF507-AA3F-464C-88DF-71E30672E623" }, { "criteria": "cpe:2.3:a:oracle:enterprise_manager_ops_center:12.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4725EA61-9BAB-4E72-9F92-ADE4624439CC" }, { "criteria": "cpe:2.3:a:oracle:enterprise_manager_ops_center:12.2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D0879FB1-58E2-4EC4-8111-044642E046BD" }, { "criteria": "cpe:2.3:a:oracle:enterprise_manager_ops_center:12.3.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C7CF2929-4CBC-4B56-87AE-F45F53BD8DD6" }, { "criteria": "cpe:2.3:a:oracle:http_server:10.1.3.5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A2E69311-C5B8-45FA-809F-ADAE4E35559D" }, { "criteria": "cpe:2.3:a:oracle:http_server:11.1.1.7.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "911FBD5E-213D-482F-81A9-C3B8CE7D903A" }, { "criteria": "cpe:2.3:a:oracle:http_server:12.1.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DACC1F65-5AF7-4CD4-ACD2-46D941A19110" }, { "criteria": "cpe:2.3:a:oracle:http_server:12.1.3.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DD4552F9-F5B9-4A52-BA5C-D32D49FABD28" }, { "criteria": "cpe:2.3:o:oracle:linux:6:-:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D7B037A8-72A6-4DFF-94B2-D688A5F6F876" }, { "criteria": "cpe:2.3:o:oracle:solaris:11.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0B1C288F-326B-497B-B26C-D26E01262DDB" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "774F1A5C-2633-4A8F-8462-B53FE0291F04", "versionEndExcluding": "10.10.4" }, { "criteria": "cpe:2.3:o:apple:mac_os_x_server:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C13EC70E-5CB6-4414-B31A-556C9B8AE5AC", "versionEndExcluding": "5.0.3" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:*", "vulnerable": true, "matchCriteriaId": "01EDA41C-6B2E-49AF-B503-EB3882265C11" }, { "criteria": "cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:*", "vulnerable": true, "matchCriteriaId": "CB66DB75-2B16-4EBF-9B93-CE49D8086E41" }, { "criteria": "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*", "vulnerable": true, "matchCriteriaId": "815D70A8-47D3-459C-A32C-9FEACA0659D1" }, { "criteria": "cpe:2.3:o:canonical:ubuntu_linux:14.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "49A63F39-30BE-443F-AF10-6245587D3359" } ], "operator": "OR" } ] } ]