CVE-2013-5704

NameCVE-2013-5704
DescriptionThe mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a security issue in httpd as such."
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-71-1
NVD severitymedium (attack range: remote)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
apache2 (PTS)wheezy2.2.22-13+deb7u6fixed
wheezy (security)2.2.22-13+deb7u12fixed
jessie2.4.10-10+deb8u11fixed
jessie (security)2.4.10-10+deb8u12fixed
stretch2.4.25-3+deb9u3fixed
stretch (security)2.4.25-3+deb9u4fixed
buster2.4.29-2fixed
sid2.4.33-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
apache2source(unstable)2.4.10-2medium
apache2sourcesqueeze2.2.16-6+squeeze14mediumDLA-71-1
apache2sourcewheezy2.2.22-13+deb7u4medium

Notes

http://marc.info/?l=apache-httpd-dev&m=139636309822854&w=2

Search for package or bug name: Reporting problems