IBM Support

PI09345: CVE-2013-6438: IBM HTTP Server mod_dav potential vulnerability

Download


Abstract

There is the potential for a denial of service due to a vulnerability in the IBM HTTP Server mod_dav module.

Download Description

PI09345 resolves the following problem:

ERROR DESCRIPTION:
A vulnerability in the mod_dav module could result in a denial of service.

z/OS is not affected.


PROBLEM SUMMARY:
Potential vulnerability for IBM HTTP Server.

PROBLEM CONCLUSION:
The module was updated to resolve the vulnerability.

This fix is targeted for IBM HTTP Server fixpacks:
- 7.0.0.33
- 8.0.0.9
- 8.5.5.2

Prerequisites

UpdateInstaller is required for IHS 7.0 and 6.1 interim fixes.

[{"PRLabel":"UpdateInstaller","PRLang":"English","PRSize":"7250000","PRPlat":{"label":"AIX","code":"PF002"},"PRURL":"http://www.ibm.com/support/docview.wss?rs=180&uid=swg21205991"}]

Download Package

The fix for IHS 6.1 is included in the PI17025 cumulative interim fix for 6.1.0.47: http://www-01.ibm.com/support/docview.wss?uid=swg24037517

On
[{"DNLabel":"8.5.0.0 - 8.5.5.2 Distributed platforms","DNDate":"15 May 2014","DNLang":"US English","DNSize":"1655660","DNPlat":{"label":"AIX","code":"PF002"},"DNURL":"http://www-933.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~WebSphere&product=ibm/WebSphere/WebSphere+Application+Server&release=All&platform=All&function=fixId&fixids=8.5.0.0-WS-WASIHS-MultiOS-IFPI09345","DNURL_FTP":" ","DDURL":" "},{"DNLabel":"8.0.0.0 - 8.0.0.8 Distributed platforms","DNDate":"15 May 2014","DNLang":"US English","DNSize":"1702283","DNPlat":{"label":"AIX","code":"PF002"},"DNURL":"http://www-933.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~WebSphere&product=ibm/WebSphere/WebSphere+Application+Server&release=All&platform=All&function=fixId&fixids=8.0.0.0-WS-WASIHS-MultiOS-IFPI09345","DNURL_FTP":" ","DDURL":" "},{"DNLabel":"7.0.0.0 - 7.0.0.31 AixPPC32","DNDate":"15 May 2014","DNLang":"US English","DNSize":"84043","DNPlat":{"label":"AIX","code":"PF002"},"DNURL":"http://www-933.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~WebSphere&product=ibm/WebSphere/WebSphere+Application+Server&release=All&platform=All&function=fixId&fixids=7.0.0.0-WS-WASIHS-AixPPC32-IFPI09345","DNURL_FTP":" ","DDURL":" "},{"DNLabel":"7.0.0.0 - 7.0.0.31 HpuxIA64","DNDate":"15 May 2014","DNLang":"US English","DNSize":"269928","DNPlat":{"label":"HP-UX","code":"PF010"},"DNURL":"http://www-933.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~WebSphere&product=ibm/WebSphere/WebSphere+Application+Server&release=All&platform=All&function=fixId&fixids=7.0.0.0-WS-WASIHS-HpuxIA64-IFPI09345","DNURL_FTP":" ","DDURL":" "},{"DNLabel":"7.0.0.0 - 7.0.0.31 HpuxPaRISC","DNDate":"15 May 2014","DNLang":"US English","DNSize":"83446","DNPlat":{"label":"HP-UX","code":"PF010"},"DNURL":"http://www-933.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~WebSphere&product=ibm/WebSphere/WebSphere+Application+Server&release=All&platform=All&function=fixId&fixids=7.0.0.0-WS-WASIHS-HpuxPaRISC-IFPI09345","DNURL_FTP":" ","DDURL":" "},{"DNLabel":"7.0.0.0 - 7.0.0.31 LinuxPPC32","DNDate":"15 May 2014","DNLang":"US English","DNSize":"74624","DNPlat":{"label":"Linux","code":"PF016"},"DNURL":"http://www-933.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~WebSphere&product=ibm/WebSphere/WebSphere+Application+Server&release=All&platform=All&function=fixId&fixids=7.0.0.0-WS-WASIHS-LinuxPPC32-IFPI09345","DNURL_FTP":" ","DDURL":" "},{"DNLabel":"7.0.0.0 - 7.0.0.31 LinuxS390","DNDate":"15 May 2014","DNLang":"US English","DNSize":"70346","DNPlat":{"label":"Linux","code":"PF016"},"DNURL":"http://www-933.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~WebSphere&product=ibm/WebSphere/WebSphere+Application+Server&release=All&platform=All&function=fixId&fixids=7.0.0.0-WS-WASIHS-LinuxS390-IFPI09345","DNURL_FTP":" ","DDURL":" "},{"DNLabel":"7.0.0.0 - 7.0.0.31 LinuxX32","DNDate":"15 May 2014","DNLang":"US English","DNSize":"66338","DNPlat":{"label":"Linux","code":"PF016"},"DNURL":"http://www-933.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~WebSphere&product=ibm/WebSphere/WebSphere+Application+Server&release=All&platform=All&function=fixId&fixids=7.0.0.0-WS-WASIHS-LinuxX32-IFPI09345","DNURL_FTP":" ","DDURL":" "},{"DNLabel":"7.0.0.0 - 7.0.0.31 SolarisSparc","DNDate":"15 May 2014","DNLang":"US English","DNSize":"93108","DNPlat":{"label":"Solaris","code":"PF027"},"DNURL":"http://www-933.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~WebSphere&product=ibm/WebSphere/WebSphere+Application+Server&release=All&platform=All&function=fixId&fixids=7.0.0.0-WS-WASIHS-SolarisSparc-IFPI09345","DNURL_FTP":" ","DDURL":" "},{"DNLabel":"7.0.0.0 - 7.0.0.31 SolarisX64","DNDate":"15 May 2014","DNLang":"US English","DNSize":"70674","DNPlat":{"label":"Solaris","code":"PF027"},"DNURL":"http://www-933.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~WebSphere&product=ibm/WebSphere/WebSphere+Application+Server&release=All&platform=All&function=fixId&fixids=7.0.0.0-WS-WASIHS-SolarisX64-IFPI09345","DNURL_FTP":" ","DDURL":" "},{"DNLabel":"7.0.0.0 - 7.0.0.31 WinX32","DNDate":"15 May 2014","DNLang":"US English","DNSize":"164448","DNPlat":{"label":"Windows","code":"PF033"},"DNURL":"http://www-933.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~WebSphere&product=ibm/WebSphere/WebSphere+Application+Server&release=All&platform=All&function=fixId&fixids=7.0.0.0-WS-WASIHS-WinX32-IFPI09345","DNURL_FTP":" ","DDURL":" "}]
[{"Product":{"code":"SSEQTJ","label":"IBM HTTP Server"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Component":"Base Server","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF010","label":"HP-UX"},{"code":"PF016","label":"Linux"},{"code":"PF027","label":"Solaris"},{"code":"PF033","label":"Windows"}],"Version":"8.5.5;8.5;8.0;7.0;6.1.0.47","Edition":"","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
07 September 2022

UID

swg24037538