Vulnerability Database

290,020

Total vulnerabilities in the database

CVE-2013-6438

The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before 2.4.8 does not properly remove whitespace characters from CDATA sections, which allows remote attackers to cause a denial of service (daemon crash) via a crafted DAV WRITE request.

  • Published: Mar 18, 2014
  • Updated: Apr 13, 2023
  • CVE: CVE-2013-6438
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 5
  • AV:N/AC:L/Au:N/C:N/I:N/A:P

No CWE or OWASP classifications available.

Software From Fixed in
apache / http_server 2.2.0 2.2.27
apache / http_server 2.4.1 2.4.9
oracle / http_server 12.1.3.0 12.1.3.0.x
oracle / http_server 12.1.2.0 12.1.2.0.x
oracle / http_server 11.1.1.7.0 11.1.1.7.0.x
oracle / http_server 10.1.3.5.0 10.1.3.5.0.x
canonical / ubuntu_linux 13.10 13.10.x
canonical / ubuntu_linux 12.10 12.10.x
canonical / ubuntu_linux 10.04 10.04.x
canonical / ubuntu_linux 12.04 12.04.x