Echo: apache2: security update to 2.4.67-1~deb13u3

critical Tenable Cloud Security Plugin ID 457981

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- CRLF injection vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in
the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series
allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting
attacks by uploading a file with a multi-line name containing HTTP header sequences and a file extension,
which leads to injection within a (1) "406 Not Acceptable" or (2) "300 Multiple Choices" HTTP response
when the extension is omitted in a request for the file. (CVE-2008-0456)

Solution

Update the apache2 library and its related packages to version 2.4.67-1~deb13u3 or later.

See Also

https://advisory.echohq.com/cve/CVE-2008-0456

Plugin Details

Severity: Critical

ID: 457981

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.59

CVSS v2

Risk Factor: Low

Base Score: 2.6

Temporal Score: 2

Vector: CVSS2#AV:N/AC:H/Au:N/C:N/I:P/A:N

CVSS Score Source: CVE-2008-0456

CVSS v3

Risk Factor: Critical

Base Score: 9.1

Temporal Score: 8.2

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 5/28/2026

Vulnerability Publication Date: 1/21/2008

Reference Information

CVE: CVE-2008-0456