CVE-2013-5704

Apache HTTP Server 2.2.22 - Auth Bypass

Title source: llm
STIX 2.1

Description

The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a security issue in httpd as such."

References (47)

Core 47
Core References
Issue Tracking, Mailing List, Third Party Advisory vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=144493176821532&w=2
Third Party Advisory x_refsource_confirm
https://support.apple.com/HT204659
Release Notes, Vendor Advisory x_refsource_confirm
http://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x/CHANGES
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201504-03
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-1249.html
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2016-0061.html
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0325.html
Third Party Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2014:174
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2523-1
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2016-0062.html
Issue Tracking, Mailing List, Third Party Advisory vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=143403519711434&w=2
Broken Link, Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-2661.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.html
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2015:2659
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2015:2660
Vendor Advisory x_refsource_confirm
https://httpd.apache.org/security/vulnerabilities_24.html
Broken Link, Exploit, Third Party Advisory x_refsource_misc
http://martin.swende.se/blog/HTTPChunked.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2015/Sep/msg00004.html
Third Party Advisory x_refsource_confirm
https://support.apple.com/HT205219
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/66550
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://marc.info/?l=apache-httpd-dev&m=139636309822854&w=2

Scores

EPSS 0.6504
EPSS Percentile 98.5%

Details

Status published
Products (50)
apache/http_server 2.2.0
apache/http_server 2.2.2
apache/http_server 2.2.3
apache/http_server 2.2.4
apache/http_server 2.2.5
apache/http_server 2.2.6
apache/http_server 2.2.8
apache/http_server 2.2.9
apache/http_server 2.2.10
apache/http_server 2.2.11
... and 40 more
Published Apr 15, 2014
Tracked Since Feb 18, 2026