CVE-2013-5704: Apache HTTP Server

Medium severity, CVSS 5.0. EPSS: 52.6% chance of exploitation in the next 30 days.

The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a security issue in httpd as such."

Affected products

  • Apache HTTP Server: version 2.2.0 only; version 2.2.2 only; version 2.2.3 only; version 2.2.4 only; version 2.2.5 only; version 2.2.6 only; …
  • Apple Mac OS X: before 10.10.4 (fixed in 10.10.4)
  • Apple Mac OS X Server: before 5.0.3 (fixed in 5.0.3)
  • Canonical Ubuntu Linux: version 10.04 only; version 12.04 only; version 14.04 only; version 14.10 only
  • Oracle Enterprise Manager Ops Center: before 12.1.4 (fixed in 12.1.4); version 12.1.4 only; version 12.2.0 only; version 12.2.1 only; version 12.3.0 only
  • Oracle HTTP Server: version 10.1.3.5.0 only; version 11.1.1.7.0 only; version 12.1.2.0 only; version 12.1.3.0 only
  • Oracle Linux: version 6 only
  • Oracle Solaris: version 11.2 only
  • Red Hat Enterprise Linux Desktop: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Eus: version 7.3 only; version 7.4 only; version 7.5 only; version 7.6 only; version 7.7 only
  • Red Hat Enterprise Linux Server: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Server Aus: version 7.3 only; version 7.4 only; version 7.6 only; version 7.7 only
  • Red Hat Enterprise Linux Server Tus: version 7.3 only; version 7.6 only; version 7.7 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only; version 7.0 only
  • Red Hat JBoss Enterprise Web Server: version 3.0.0 only; version 2.0.0 only

Published 2014-04-15. Last modified 2026-06-16.