From 89d9998222bcf793d5a3dfd1388176c0b1b5bdeb Mon Sep 17 00:00:00 2001 From: Olli Hauer Date: Fri, 5 Jul 2013 21:06:15 +0000 Subject: [PATCH] - document apache22 CVE-2013-1862 (mod_rewrite) Update to apache22-2.2.25 is ready to commit. Until now there is no official announcement from apache.org so we hold the update back until we have official checksums. --- security/vuxml/vuln.xml | 45 +++++++++++++++++++++++++++++++++++++++++ 1 file changed, 45 insertions(+) diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index d109da19a03c..5f41cd552ba6 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -51,6 +51,51 @@ Note: Please add new entries to the beginning of this file. --> + + apache22 -- mod_rewrite vulnerability + + + apache22 + 2.2.02.2.25 + + + apache22-event-mpm + 2.2.02.2.25 + + + apache22-itk-mpm + 2.2.02.2.25 + + + apache22-peruser-mpm + 2.2.02.2.25 + + + apache22-worker-mpm + 2.2.02.2.25 + + + + +

Apache HTTP SERVER PROJECT reports:

+
+

The mod_rewrite module in the Apache HTTP Server 2.2.x before + 2.2.25 writes data to a log file without sanitizing + non-printable characters, which might allow remote attackers to + execute arbitrary commands via an HTTP request containing an + escape sequence for a terminal emulator.

+
+ +
+ + CVE-2013-1862 + + + 2013-06-21 + 2013-07-05 + +
+ phpMyAdmin -- Global variable scope injection