Apache HTTP Server 2.0.x and 2.2.x does not sanitize the HTTP Method specifier header from an HTTP request when it is reflected back in a "413 Request Entity Too Large" error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated via an HTTP request containing an invalid Content-length value, a similar issue to CVE-2006-3918.
CVSS Details
- CVSS 3.1 Base Score: 6.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Httpd | — | Upgrade to Apache HTTPD version 2.2.5Upgrade to Apache HTTPD version 2.0.60 | Apr 12, 2012 | Dec 3, 2007 |
| Apple Osx Apache | — | Apply OS X security update 2008-002 | Dec 16, 2011 | Dec 3, 2007 |
| Debian | — | Upgrade apache2 | Jul 30, 2024 | Dec 3, 2007 |
| Gentoo Linux | — | Upgrade www-servers/apache. | Oct 30, 2017 | Dec 3, 2007 |
| Hpux | — | Update hpuxwsAPACHE.MOD_PERL to the latest versionUpdate hpuxwsAPCH32.MOD_PERL2 to the latest versionUpdate hpuxwsAPCH32.APACHE2 to the latest versionUpdate hpuxwsAPACHE.MOD_JK2 to the latest versionUpdate hpuxwsAPCH32.AUTH_LDAP2 to the latest versionUpdate hpuxwsAPACHE.MOD_PERL2 to the latest versionUpdate hpuxwsAPACHE.MOD_JK to the latest versionUpdate hpuxwsAPACHE.AUTH_LDAP2 to the latest versionUpdate hpuxwsAPACHE.APACHE to the latest versionUpdate hpuxwsAPCH32.PHP to the latest versionUpdate hpuxwsAPCH32.MOD_JK2 to the latest versionUpdate hpuxwsAPACHE.WEBPROXY to the latest versionUpdate hpuxwsAPACHE.PHP to the latest versionUpdate hpuxwsAPCH32.WEBPROXY to the latest versionUpdate hpuxwsAPCH32.MOD_PERL to the latest versionUpdate hpuxwsAPACHE.AUTH_LDAP to the latest versionUpdate hpuxwsAPACHE.PHP2 to the latest versionUpdate hpuxwsAPCH32.MOD_JK to the latest versionUpdate hpuxwsAPCH32.PHP2 to the latest versionUpdate hpuxwsAPCH32.APACHE to the latest versionUpdate hpuxwsAPACHE.APACHE2 to the latest versionUpdate hpuxwsAPCH32.AUTH_LDAP to the latest version | Aug 11, 2017 | Dec 3, 2007 |
| Suse | — | Upgrade apache2-utilsUpgrade apache2-docUpgrade apache2-example-pagesUpgrade suse-releaseUpgrade apache2-workerUpgrade apache2Upgrade apache2-develUpgrade apache2-preforkUpgrade libapr0 | Feb 17, 2015 | Dec 3, 2007 |
| Ubuntu | — | Upgrade apache2-commonUpgrade apache2-mpm-workerUpgrade apache2-mpm-preforkUpgrade apache2-mpm-eventUpgrade apache2-mpm-perchildUpgrade apache2.2-common | Nov 8, 2024 | Dec 3, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub