mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade apache2 | Aug 30, 2017 | Jul 10, 2013 |
| Apache Httpd | — | Upgrade to the latest version of Apache HTTPD | Jul 29, 2013 | Jul 10, 2013 |
| Apple Osx Apache | — | Apply OS X security update 2014-001Upgrade macOS to the latest version | Mar 3, 2014 | Jul 10, 2013 |
| Centos_linux | — | Upgrade mod_sslUpgrade httpd-manualUpgrade httpd-develUpgrade httpd-toolsUpgrade httpd | Dec 1, 2016 | Jul 10, 2013 |
| Debian | — | Upgrade apache2 | Jul 30, 2024 | Jul 10, 2013 |
| Freebsd | — | Upgrade apache24Upgrade apache22-itk-mpmUpgrade apache22-event-mpmUpgrade apache22-peruser-mpmUpgrade apache22Upgrade apache22-worker-mpm | Dec 10, 2025 | Jul 20, 2013 |
| Gentoo Linux | — | Upgrade www-servers/apache. | Oct 30, 2017 | Jul 10, 2013 |
| Hpux | — | Update hpuxws22APCH32.AUTH_LDAP to the latest versionUpdate hpuxws22APCH32.PHP2 to the latest versionUpdate hpuxws22APCH32.PHP to the latest versionUpdate hpuxws22APACHE.AUTH_LDAP to the latest versionUpdate hpuxws22APACHE.MOD_JK to the latest versionUpdate hpuxws22APACHE.PHP2 to the latest versionUpdate hpuxws22APACHE.WEBPROXY to the latest versionUpdate hpuxws22APACHE.PHP to the latest versionUpdate hpuxws22APCH32.MOD_JK2 to the latest versionUpdate hpuxws22APCH32.MOD_PERL to the latest versionUpdate hpuxws22APCH32.APACHE to the latest versionUpdate hpuxws22APCH32.WEBPROXY to the latest versionUpdate hpuxws22APCH32.WEBPROXY2 to the latest versionUpdate hpuxws22APCH32.AUTH_LDAP2 to the latest versionUpdate hpuxws22APACHE.APACHE2 to the latest versionUpdate hpuxws22APACHE.MOD_PERL to the latest versionUpdate hpuxws22APACHE.WEBPROXY2 to the latest versionUpdate hpuxws22APCH32.APACHE2 to the latest versionUpdate hpuxws22APACHE.AUTH_LDAP2 to the latest versionUpdate hpuxws22APACHE.MOD_PERL2 to the latest versionUpdate hpuxws22APACHE.APACHE to the latest versionUpdate hpuxws22APCH32.MOD_JK to the latest versionUpdate hpuxws22APCH32.MOD_PERL2 to the latest versionUpdate hpuxws22APACHE.MOD_JK2 to the latest version | Aug 11, 2017 | Jul 10, 2013 |
| Ibm Http_server | — | Apply IBM HTTP Server version 8.0.0.7 or laterApply IBM HTTP Server version 8.5.5.1 or laterApply IBM HTTP Server Interim Fix PM89996 | Jun 22, 2018 | Jul 10, 2013 |
| Ibm Was | — | Upgrade to minimal fix pack levels as required by interim fixes and then apply latest Interim Fix. | Jul 10, 2013 | Jul 10, 2013 |
| Oracle Solaris | — | Upgrade web/server/apache-22/documentation to version 2.2.25-0.175.1.11.0.4.0 on Solaris 11.1Upgrade web/server/apache-22 to version 2.2.25-0.175.1.11.0.4.0 on Solaris 11.1 | May 29, 2017 | Jul 10, 2013 |
| Oracle_linux | — | Upgrade httpd-develUpgrade mod_sslUpgrade httpdUpgrade httpd-manualUpgrade httpd-tools | Oct 16, 2024 | Jul 10, 2013 |
| Red Hat Jboss Eap | — | Upgrade Red Hat JBoss EAP to the latest version | Sep 19, 2024 | May 23, 2013 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 23, 2013 |
| Suse | — | Upgrade apache2-develUpgrade apache2-preforkUpgrade sle-sdk-releaseUpgrade apache2-docUpgrade apache2-example-pagesUpgrade apache2-itkUpgrade apache2Upgrade apache2-utilsUpgrade apache2-eventUpgrade apache2-worker | Dec 12, 2013 | Jul 10, 2013 |
| Ubuntu | — | Upgrade apache2.2-common | Nov 8, 2024 | Jul 10, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub