PT-2003-1461 · Apache · Apache Portable Runtime (Apr) Library+2

Publicado

2003-05-30

·

Atualizado

2021-06-06

·

CVE-2003-0245

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: Apache HTTP Server versions 2.0.37 through 2.0.45
Description: The issue is related to a problem in the apr psprintf function within the Apache Portable Runtime (APR) library. This allows remote attackers to potentially cause a denial of service (crash) and possibly execute arbitrary code by sending long strings. This can be achieved through various vectors, including the use of XML objects to mod dav.
Recommendations: For Apache HTTP Server versions 2.0.37 through 2.0.45, update to a version that includes a fix for the apr psprintf function issue to prevent potential denial of service and arbitrary code execution attacks.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2003-0245

Produtos afetados

Apache Http Server
Apache Portable Runtime (Apr) Library
Mod Dav