Back

MEDIUM

httpd: Garbage before http method name is not escaped in a reply in case of errorneous request

Published Dec 3, 2007

Description

Apache HTTP Server 2.0.x and 2.2.x does not sanitize the HTTP Method specifier header from an HTTP request when it is reflected back in a "413 Request Entity Too Large" error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated via an HTTP request containing an invalid Content-length value, a similar issue to CVE-2006-3918.

Affected products

Remediation

Red Hat statement

Red Hat does not consider this issue to be a vulnerability. In order to exploit this for cross-site scripting, the attacker would have to get the victim to supply an arbitrary malformed HTTP method to a target site. However, this has been fixed in Red Hat Enterprise Linux 5 via RHBA-2009:0185 as a bug fix.

Metrics

References (35)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 3, 2007
Updated Aug 7, 2024
Reserved Dec 3, 2007
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date Nov 30, 2007