CVE-2013-5704
Publication date 15 April 2014
Last updated 24 July 2024
Ubuntu priority
The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a security issue in httpd as such."
Status
Package | Ubuntu Release | Status |
---|---|---|
apache2 | ||
14.04 LTS trusty |
Fixed 2.4.7-1ubuntu4.4
|
|
Notes
References
Related Ubuntu Security Notices (USN)
- USN-2523-1
- Apache HTTP Server vulnerabilities
- 10 March 2015