The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before 2.4.8 does not properly remove whitespace characters from CDATA sections, which allows remote attackers to cause a denial of service (daemon crash) via a crafted DAV WRITE request.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Http_server | Apache | 2.2.0 (including) | 2.2.27 (excluding) |
Http_server | Apache | 2.4.1 (including) | 2.4.9 (excluding) |
Apache2 | Ubuntu | devel | * |
Apache2 | Ubuntu | lucid | * |
Apache2 | Ubuntu | precise | * |
Apache2 | Ubuntu | quantal | * |
Apache2 | Ubuntu | saucy | * |
Apache2 | Ubuntu | upstream | * |
Red Hat Enterprise Linux 5 | RedHat | httpd-0:2.2.3-85.el5_10 | * |
Red Hat Enterprise Linux 6 | RedHat | httpd-0:2.2.15-30.el6_5 | * |
Red Hat JBoss Enterprise Application Platform 6.2 | RedHat | * | |
Red Hat JBoss Enterprise Application Platform 6.2 for RHEL 5 | RedHat | httpd-0:2.2.22-27.ep6.el5 | * |
Red Hat JBoss Enterprise Application Platform 6.2 for RHEL 6 | RedHat | httpd-0:2.2.22-27.ep6.el6 | * |
Red Hat JBoss Enterprise Web Server 2 for RHEL 5 | RedHat | httpd-0:2.2.22-27.ep6.el5 | * |
Red Hat JBoss Enterprise Web Server 2 for RHEL 6 | RedHat | httpd-0:2.2.22-27.ep6.el6 | * |
Red Hat JBoss Web Server 2.0 | RedHat | httpd | * |