CVE-2013-1896: Apache HTTP Server
Medium severity, CVSS 4.3. EPSS: 29.5% chance of exploitation in the next 30 days.
mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.
Affected products
- Apache HTTP Server: from 2.2.0, before 2.2.25 (fixed in 2.2.25); from 2.4.1, before 2.4.6 (fixed in 2.4.6)
- Canonical Ubuntu Linux: version 10.04 only; version 12.04 only; version 12.10 only; version 13.04 only
- Opensuse Opensuse: version 11.4 only; version 12.2 only; version 12.3 only
- Red Hat Enterprise Linux Desktop: version 5.0 only; version 6.0 only
- Red Hat Enterprise Linux Eus: version 5.9 only; version 6.4 only
- Red Hat Enterprise Linux Server: version 5.0 only; version 6.0 only
- Red Hat Enterprise Linux Server Aus: version 5.9 only; version 6.4 only
- Red Hat Enterprise Linux Workstation: version 5.0 only; version 6.0 only
- Red Hat JBoss Enterprise Application Platform: version 6.0.0 only; version 6.4.0 only
Published 2013-07-10. Last modified 2026-06-16.