Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Ubuntu 13.04: USN-1903-1 Critical: Apache Server Command Injection

ubuntu
Calendar Grey July 15, 2013
Scroller Ubuntu
Security Advisory USN-1903-2 outlines updates for Apache HTTP Server that fix various security weaknesses for Ubuntu users.
Several security issues were fixed in the Apache HTTP Server.

Summary

Several security issues were fixed in the Apache HTTP Server.

Software Description:

- apache2: Apache HTTP server

Details:

It was discovered that the mod_rewrite module incorrectly sanitized non-printable characters before writing data to log files. A remote attacker

could possibly use this flaw to execute arbitrary commands by injecting

escape sequences in the log file. (CVE-2013-1862)

It was discovered that the mod_dav module incorrectly handled certain MERGE

requests. A remote attacker could use this issue to cause the server to

stop responding, resulting in a denial of service. (CVE-2013-1896)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.04:
  apache2.2-common                2.2.22-6ubuntu5.1

Ubuntu 12.10:
  apache2.2-common                2.2.22-6ubuntu2.3

Ubuntu 12.04 LTS:
  apache2.2-common                2.2.22-1ubuntu1.4

Ubuntu 10.04 LTS:
  apache2.2-common                2.2.14-5ubuntu8.12

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1903-1

CVE-2013-1862, CVE-2013-1896

Severity
critical
Lowest
Low
Medium
High
Critical

July 15, 2013

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.