---
title: "CVE-2006-3918\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2006-3918?format=md
keywords: index, follow
---

# CVE-2006-3918

Publication date 27 July 2006

Last updated 24 July 2024

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

http\_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before
6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58,
and 2.2 before 2.2.2, does not sanitize the Expect header from an HTTP
request when it is reflected back in an error message, which might allow
cross-site scripting (XSS) style attacks using web client components that
can send arbitrary headers in requests, as demonstrated using a Flash SWF
file.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2006-3918?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| apache | 9.10 karmic | Not in release |
| 9.04 jaunty | Not in release |
| 8.10 intrepid | Not in release |
| 8.04 LTS hardy | Not in release |
| 7.10 gutsy | Not in release |
| 7.04 feisty | Fixed 1.3.34-4ubuntu1 |
| 6.10 edgy | Fixed 1.3.34-4ubuntu1 |
| 6.06 LTS dapper | Ignored end of life |
| apache2 | 9.10 karmic | Fixed 2.2.4-3 |
| 9.04 jaunty | Fixed 2.2.4-3 |
| 8.10 intrepid | Fixed 2.2.4-3 |
| 8.04 LTS hardy | Fixed 2.2.4-3 |
| 7.10 gutsy | Fixed 2.2.4-3 |
| 7.04 feisty | Fixed 2.2.3-3.2ubuntu0.1 |
| 6.10 edgy | Fixed 2.0.55-4ubuntu4.1 |
| 6.06 LTS dapper | Fixed 2.0.55-4ubuntu2.3 |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2006-3918?format=md#patch-details)

## Notes

---

### [jdstrand](https://launchpad.net/~jdstrand)

verify edgy is fixed

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| apache2 | * Vendor:   <http://snapshot.debian.net/cgi-bin/packages.cgi> |

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3918)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2006-3918)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2006-3918)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2006-3918)

### Related Ubuntu Security Notices (USN)

+ [USN-575-1](https://usn.ubuntu.com/USN-575-1)
+ Apache vulnerabilities
+ 4 February 2008

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2006-3918>
