CVE-2013-5704: Apache HTTP Server
Medium severity, CVSS 5.0. EPSS: 52.6% chance of exploitation in the next 30 days.
The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a security issue in httpd as such."
Affected products
- Apache HTTP Server: version 2.2.0 only; version 2.2.2 only; version 2.2.3 only; version 2.2.4 only; version 2.2.5 only; version 2.2.6 only; …
- Apple Mac OS X: before 10.10.4 (fixed in 10.10.4)
- Apple Mac OS X Server: before 5.0.3 (fixed in 5.0.3)
- Canonical Ubuntu Linux: version 10.04 only; version 12.04 only; version 14.04 only; version 14.10 only
- Oracle Enterprise Manager Ops Center: before 12.1.4 (fixed in 12.1.4); version 12.1.4 only; version 12.2.0 only; version 12.2.1 only; version 12.3.0 only
- Oracle HTTP Server: version 10.1.3.5.0 only; version 11.1.1.7.0 only; version 12.1.2.0 only; version 12.1.3.0 only
- Oracle Linux: version 6 only
- Oracle Solaris: version 11.2 only
- Red Hat Enterprise Linux Desktop: version 6.0 only; version 7.0 only
- Red Hat Enterprise Linux Eus: version 7.3 only; version 7.4 only; version 7.5 only; version 7.6 only; version 7.7 only
- Red Hat Enterprise Linux Server: version 6.0 only; version 7.0 only
- Red Hat Enterprise Linux Server Aus: version 7.3 only; version 7.4 only; version 7.6 only; version 7.7 only
- Red Hat Enterprise Linux Server Tus: version 7.3 only; version 7.6 only; version 7.7 only
- Red Hat Enterprise Linux Workstation: version 6.0 only; version 7.0 only
- Red Hat JBoss Enterprise Web Server: version 3.0.0 only; version 2.0.0 only
Published 2014-04-15. Last modified 2026-06-16.