PT-2002-2572 · Apache · Apache Http Server
Published
2002-12-31
·
Updated
2024-02-09
·
CVE-2002-1850
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Apache versions 2.0.39 through 2.0.40
Description
The issue allows local users and possibly remote attackers to cause a denial of service, resulting in hang and memory consumption. This occurs when a CGI script sends a large amount of data to stderr, causing a read/write deadlock between httpd and the CGI script.
Recommendations
For Apache versions 2.0.39 and 2.0.40, consider restricting the amount of data that can be sent to stderr by CGI scripts to prevent the read/write deadlock. As a temporary workaround, consider disabling the CGI script functionality until a patch is available.
Exploit
Fix
DoS
Improper Locking
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Http Server