CVE-2013-1862Improper Input Validation in Apache Http Server

Severity
5.1MEDIUMNVD
EPSS
39.6%
top 2.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 10
Latest updateMay 13

Description

mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containing an escape sequence for a terminal emulator.

CVSS vector

AV:N/AC:H/C:P/I:P/A:PExploitability: 4.9 | Impact: 6.4

Affected Packages7 packages

NVDapache/http_server2.0.02.0.65+1
NVDoracle/http_server4 versions+3
NVDopensuse/opensuse11.4, 12.2, 12.3+2

Also affects: Ubuntu Linux 10.04, 12.04, 12.10, 13.04, Enterprise Linux 5.9, 6.4

Patches

🔴Vulnerability Details

3
GHSA
GHSA-wp7w-p549-c3xq: mod_rewrite2022-05-13
CVEList
CVE-2013-1862: mod_rewrite2013-06-10
OSV
CVE-2013-1862: mod_rewrite2013-06-10

📋Vendor Advisories

4
Ubuntu
Apache HTTP Server vulnerabilities2013-07-15
Cisco
Apache HTTP Server mod_rewrite Log File Manipulation Vulnerability2013-05-30
Red Hat
httpd: mod_rewrite allows terminal escape sequences to be written to the log file2013-04-19
Debian
CVE-2013-1862: apache2 - mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2...2013

💬Community

1
Bugzilla
CVE-2013-1862 httpd: mod_rewrite allows terminal escape sequences to be written to the log file2013-04-19
CVE-2013-1862 — Improper Input Validation in Apache | cvebase