PT-2003-1461 · Apache · Apache Portable Runtime (Apr) Library+2
Published
2003-05-30
·
Updated
2021-06-06
·
CVE-2003-0245
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions:
Apache HTTP Server versions 2.0.37 through 2.0.45
Description:
The issue is related to a problem in the apr psprintf function within the Apache Portable Runtime (APR) library. This allows remote attackers to potentially cause a denial of service (crash) and possibly execute arbitrary code by sending long strings. This can be achieved through various vectors, including the use of XML objects to mod dav.
Recommendations:
For Apache HTTP Server versions 2.0.37 through 2.0.45, update to a version that includes a fix for the apr psprintf function issue to prevent potential denial of service and arbitrary code execution attacks.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Http Server
Apache Portable Runtime (Apr) Library
Mod Dav