CVE-2013-6438: Apache HTTP Server

Medium severity, CVSS 5.0. EPSS: 27.5% chance of exploitation in the next 30 days.

The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before 2.4.8 does not properly remove whitespace characters from CDATA sections, which allows remote attackers to cause a denial of service (daemon crash) via a crafted DAV WRITE request.

Affected products

  • Apache HTTP Server: from 2.2.0, before 2.2.27 (fixed in 2.2.27); from 2.4.1, before 2.4.9 (fixed in 2.4.9)
  • Canonical Ubuntu Linux: version 10.04 only; version 12.04 only; version 12.10 only; version 13.10 only
  • Oracle HTTP Server: version 10.1.3.5.0 only; version 11.1.1.7.0 only; version 12.1.2.0 only; version 12.1.3.0 only

Published 2014-03-18. Last modified 2026-06-17.