PT-2002-2572 · Apache · Apache Http Server
CVE-2002-1850
·
Publicado
2002-12-31
·
Atualizado
2024-02-09
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Apache versions 2.0.39 through 2.0.40
Description
The issue allows local users and possibly remote attackers to cause a denial of service, resulting in hang and memory consumption. This occurs when a CGI script sends a large amount of data to stderr, causing a read/write deadlock between httpd and the CGI script.
Recommendations
For Apache versions 2.0.39 and 2.0.40, consider restricting the amount of data that can be sent to stderr by CGI scripts to prevent the read/write deadlock. As a temporary workaround, consider disabling the CGI script functionality until a patch is available.
Exploit
Correção
DoS
Improper Locking
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Apache Http Server