PT-2003-1704 · Apache · Apache+1
Publicado
2003-10-27
·
Atualizado
2021-06-06
·
CVE-2003-0542
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Apache versions prior to 1.3.29
Description:
The issue is related to multiple stack-based buffer overflows in the mod alias and mod rewrite modules. This can be triggered by using a regular expression with more than 9 captures, potentially leading to a denial of service (crash) or the execution of arbitrary code. An attacker would need to create a carefully crafted configuration file, such as .htaccess or httpd.conf, to exploit this issue.
Recommendations:
For Apache versions prior to 1.3.29, update to version 1.3.29 or later to resolve the issue. As a temporary workaround, consider restricting access to the mod alias and mod rewrite modules until a patch is applied. Avoid using regular expressions with more than 9 captures in configuration files for these modules until the issue is resolved.
Correção
DoS
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Apache
Apache Http Server