ClearOS Documentation

×

Warning

301 error for file:https://clearos.com/dokuwiki2/lib/exe/css.php?t=dokuwiki&tseed=82873f9c9a1f5784b951644363f20ef8

User Tools

Site Tools


CVE 2013-6438

'The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before 2.4.8 does not properly remove whitespace characters from CDATA sections, which allows remote attackers to cause a denial of service (daemon crash) via a crafted DAV WRITE request.'

ClearCenter response

ClearCenter response

This issue affects ClearOS 6.

Short response

This issue was fixed in the backported fixes of versions of:

  • httpd version 2.2.15-30 or later in ClearOS 6
  • webconfig-httpd version 2.2.15-30 or later in ClearOS 6

Some scans may claim that ClearOS 7 is vulnerable to this exploit. No version of ClearOS 7 has this vulnerability.

Long response

This issue was fixed during the maintenance cycle of ClearOS 6. No version of ClearOS 7 has been vulnerable to this vulnerability. ClearOS systems that are up to date do not suffer from this vulnerability. Some vulnerability scanning software may report this bug because their only method for determining the issue is to check the http version number since the exploit requires specific web configurations and has not other means for testing vulnerability. In ClearOS, version numbers stay consistent through the product's life-cycle and will produce a false positive on this issue if the testing software considers only the http version and not the ClearOS patch level.

Resolution

If you are running ClearOS 6, please ensure that you are running the latest updates:

yum update

You may also validate your version by running:

rpm -qi httpd

You should validate that you are running:

ClearOS 6
  • httpd version 2.2.15-30 or later
  • webconfig-httpd version 2.2.15-30 or later
content/en_us/announcements_cve_cve-2013-6438.txt · Last modified: 2018/09/30 21:08 by dloper

https://clearos.com/dokuwiki2/lib/exe/indexer.php?id=content%3Aen_us%3Aannouncements_cve_cve-2013-6438&1558439479