CVE-2013-5704
apache2 - security update
EPSS 60.2%
描述
The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a security issue in httpd as such."
如何修補 CVE-2013-5704
要修補 CVE-2013-5704,請將受影響套件升級到下列已修補版本。
- Debian/apache2—升級至 2.4.10-2 或更新版本
- Debian/apache2—升級至 2.2.16-6+squeeze14 或更新版本
CVE-2013-5704 正在被利用嗎?
可能 — EPSS 為 60.2%,屬於高被利用機率區間,建議優先修補。
受影響套件(2)
- from 0, < 2.4.10-2
- from 0, < 2.2.16-6+squeeze14