Description
Two potential security issues have been fixed in Apache version 1.3.34:
- If a request contains both Transfer-Encoding and Content-Length headers, remove the Content-Length, mitigating some HTTP Request Splitting/Spoofing attacks.
- Added TraceEnable [on|off|extended] per-server directive to alter the behavior of the TRACE method.
Remediation
Upgrade Apache to the latest version.
References
Related Vulnerabilities
Python Incorrect Type Conversion or Cast Vulnerability (CVE-2020-10735)
WordPress Plugin MDC Private Message Cross-Site Scripting (1.0.0)
PHP NULL Pointer Dereference Vulnerability (CVE-2016-10162)
Atlassian Jira Incorrect Default Permissions Vulnerability (CVE-2019-20106)
WordPress Plugin Permalink Manager Lite Cross-Site Scripting (2.2.14)