PT-2003-1995 · Apache · Apache+1

Publicado

2003-10-15

·

Atualizado

2021-06-06

·

CVE-2003-0993

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Apache versions prior to 1.3.30
Description The issue arises from improper parsing of Allow/Deny rules using IP addresses without a netmask on big-endian 64-bit platforms. This could allow remote attackers to bypass intended access restrictions. A bug in the parsing of these rules causes them to fail to match as intended.
Recommendations For Apache versions prior to 1.3.30, update to version 1.3.30 or later to resolve the issue. As a temporary workaround, consider using IP addresses with a netmask in Allow/Deny rules to minimize the risk of exploitation. Restrict access to sensitive areas of the server until the update can be applied.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2003-0993

Produtos afetados

Apache
Apache Http Server