PT-2003-1704 · Apache · Apache+1
Published
2003-10-27
·
Updated
2021-06-06
·
CVE-2003-0542
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Apache versions prior to 1.3.29
Description:
The issue is related to multiple stack-based buffer overflows in the mod alias and mod rewrite modules. This can be triggered by using a regular expression with more than 9 captures, potentially leading to a denial of service (crash) or the execution of arbitrary code. An attacker would need to create a carefully crafted configuration file, such as .htaccess or httpd.conf, to exploit this issue.
Recommendations:
For Apache versions prior to 1.3.29, update to version 1.3.29 or later to resolve the issue. As a temporary workaround, consider restricting access to the mod alias and mod rewrite modules until a patch is applied. Avoid using regular expressions with more than 9 captures in configuration files for these modules until the issue is resolved.
Fix
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache
Apache Http Server