CVE-2013-1862: Apache HTTP Server
Medium severity, CVSS 5.1. EPSS: 24.9% chance of exploitation in the next 30 days.
mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containing an escape sequence for a terminal emulator.
Affected products
- Apache HTTP Server: from 2.0.0, before 2.0.65 (fixed in 2.0.65); from 2.2.0, before 2.2.25 (fixed in 2.2.25)
- Canonical Ubuntu Linux: version 10.04 only; version 12.04 only; version 12.10 only; version 13.04 only
- Opensuse Opensuse: version 11.4 only; version 12.2 only; version 12.3 only
- Oracle HTTP Server: version 10.1.3.5.0 only; version 11.1.1.7.0 only; version 12.1.2.0 only; version 12.1.3.0 only
- Red Hat Enterprise Linux Desktop: version 5.0 only; version 6.0 only
- Red Hat Enterprise Linux Eus: version 5.9 only; version 6.4 only
- Red Hat Enterprise Linux Server: version 5.0 only; version 6.0 only
- Red Hat Enterprise Linux Server Aus: version 5.9 only; version 6.4 only
- Red Hat Enterprise Linux Workstation: version 5.0 only; version 6.0 only
- Red Hat JBoss Enterprise Application Platform: version 6.0.0 only; version 6.4.0 only
Published 2013-06-10. Last modified 2026-06-16.