PT-2003-1461 · Apache · Apache Portable Runtime (Apr) Library+2

Published

2003-05-30

·

Updated

2021-06-06

·

CVE-2003-0245

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: Apache HTTP Server versions 2.0.37 through 2.0.45
Description: The issue is related to a problem in the apr psprintf function within the Apache Portable Runtime (APR) library. This allows remote attackers to potentially cause a denial of service (crash) and possibly execute arbitrary code by sending long strings. This can be achieved through various vectors, including the use of XML objects to mod dav.
Recommendations: For Apache HTTP Server versions 2.0.37 through 2.0.45, update to a version that includes a fix for the apr psprintf function issue to prevent potential denial of service and arbitrary code execution attacks.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2003-0245

Affected Products

Apache Http Server
Apache Portable Runtime (Apr) Library
Mod Dav