CVE-2013-1896
EPSS 44.0%
Description
mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.
How to fix CVE-2013-1896
To remediate CVE-2013-1896, upgrade the affected package to a fixed version below.
- Debian/apache2—upgrade to 2.4.6-1 or later
Is CVE-2013-1896 being exploited?
Moderate — EPSS is 44.0%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 2.4.6-1