mod_headers CVE-2013-5704
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
apache2 (Ubuntu) |
Fix Released
|
Undecided
|
Unassigned | ||
Lucid |
Fix Released
|
Low
|
Unassigned | ||
Precise |
Fix Released
|
Low
|
Unassigned | ||
Trusty |
Fix Released
|
Low
|
Unassigned | ||
Utopic |
Fix Released
|
Low
|
Unassigned | ||
Vivid |
Fix Released
|
Undecided
|
Unassigned |
Bug Description
The cache_merge_
Nothing in the 14.04 LTS apache2 2.4.7-1ubuntu4.1 changelog shows that this has been address:
http://
Looks like it is fixed in apache2 (2.4.10-2) unstable; urgency=medium
* Pull changes from upstream 2.4.x branch up to r1626207
+ Security Fix for CVE-2013-5704: HTTP trailers could be used to
replace HTTP headers late during request processing, potentially
undoing or otherwise confusing modules that examined or modified
request headers earlier.
Adds "MergeTrailers" directive to restore legacy behavior.
information type: | Private Security → Public Security |
Changed in apache2 (Ubuntu Lucid): | |
status: | New → Confirmed |
Changed in apache2 (Ubuntu Vivid): | |
status: | New → Fix Released |
Changed in apache2 (Ubuntu Utopic): | |
status: | New → Confirmed |
Changed in apache2 (Ubuntu Trusty): | |
status: | New → Confirmed |
Changed in apache2 (Ubuntu Precise): | |
status: | New → Confirmed |
Changed in apache2 (Ubuntu Lucid): | |
importance: | Undecided → Low |
Changed in apache2 (Ubuntu Precise): | |
importance: | Undecided → Low |
Changed in apache2 (Ubuntu Trusty): | |
importance: | Undecided → Low |
Changed in apache2 (Ubuntu Utopic): | |
importance: | Undecided → Low |
If you must use the mod, it looks like a good work around until this is fixed, is to install Ondřej Surý PPA for Apache2.x. The PPA has apache 2.4.12 for ubuntu trusty and other versions. /launchpad. net/~ondrej/ +archive/ ubuntu/ apache2
https:/
I have been running 2.4.12 for a few days now on trusty with no issues and the PCI scanners are happy.