cbcvebase.
CVE-2013-1862
published 2013-06-10

CVE-2013-1862: mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters…

medium5.1CVSS 3.1
AVNACHAuNCPIPAP
mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containing an escape sequence for a terminal emulator.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
apachehttp_server>= 2.0.0 < 2.0.652.0.65
apachehttp_server>= 2.2.0 < 2.2.252.2.25
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianapache2< apache2 2.4.1-1 (bookworm)apache2 2.4.1-1 (bookworm)
opensuseopensuse
opensuseopensuse
opensuseopensuse
oraclehttp_server
oraclehttp_server
oraclehttp_server
oraclehttp_server
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_workstation
redhatenterprise_linux_workstation
redhatjboss_enterprise_application_platform

CVSS provenance

nvd5.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
osv5.1MEDIUM