CVE Database
/

CVE-2013-5704

Back to search

CVE-2013-5704

Published: Apr 15, 2014

Modified: Aug 6, 2024

PUBLISHED

Description

The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a security issue in httpd as such."

VendorProductVersions

n/a

n/a

affected
n/a

References

HPSBUX03512
vendor-advisory
x_refsource_HP
GLSA-201504-03
vendor-advisory
x_refsource_GENTOO
RHSA-2015:1249
vendor-advisory
x_refsource_REDHAT
RHSA-2016:0061
vendor-advisory
x_refsource_REDHAT
RHSA-2015:0325
vendor-advisory
x_refsource_REDHAT
MDVSA-2014:174
vendor-advisory
x_refsource_MANDRIVA
USN-2523-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2016:0062
vendor-advisory
x_refsource_REDHAT
SSRT102066
vendor-advisory
x_refsource_HP
RHSA-2015:2661
vendor-advisory
x_refsource_REDHAT
SSRT102254
vendor-advisory
x_refsource_HP
APPLE-SA-2015-04-08-2
vendor-advisory
x_refsource_APPLE
RHSA-2015:2659
vendor-advisory
x_refsource_REDHAT
RHSA-2015:2660
vendor-advisory
x_refsource_REDHAT
APPLE-SA-2015-09-16-4
vendor-advisory
x_refsource_APPLE
HPSBUX03337
vendor-advisory
x_refsource_HP
66550
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now