Back

HIGH

Apache HTTP Server: mod_dav out of bounds read, or write of zero byte

Published Jan 17, 2023

Description

A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header value sent. This could cause the process to crash.

This issue affects Apache HTTP Server 2.4.54 and earlier.

Affected products

Remediation

Red Hat statement

This flaw only affects configurations with mod_dav loaded and configured. Also, if there is no WebDAV repository configured, the server is not affected and no further mitigation is needed. For more information about the mitigation, check the mitigation section below. The httpd mod_dav module is enabled by default on Red Hat Enterprise Linux 6, 7, 8, 9, and in RHSCL. However, there is no WebDAV repository configured by default. This flaw has been rated as having a security impact of moderate, and is not currently planned to be addressed in future updates of Red Hat Enterprise Linux 7. Red Hat Enterprise Linux 7 is now in Maintenance Support 2 Phase of the support and maintenance life cycle. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata.

Red Hat mitigation

Disabling mod_dav and restarting httpd will mitigate this flaw.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Jan 17, 2023
Updated Feb 13, 2025
Reserved Sep 1, 2022
CISA Vulnrichment
Updated Aug 1, 2024
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Jan 17, 2023