PT-2003-1704 · Apache · Apache+1

Published

2003-10-27

·

Updated

2021-06-06

·

CVE-2003-0542

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Apache versions prior to 1.3.29
Description: The issue is related to multiple stack-based buffer overflows in the mod alias and mod rewrite modules. This can be triggered by using a regular expression with more than 9 captures, potentially leading to a denial of service (crash) or the execution of arbitrary code. An attacker would need to create a carefully crafted configuration file, such as .htaccess or httpd.conf, to exploit this issue.
Recommendations: For Apache versions prior to 1.3.29, update to version 1.3.29 or later to resolve the issue. As a temporary workaround, consider restricting access to the mod alias and mod rewrite modules until a patch is applied. Avoid using regular expressions with more than 9 captures in configuration files for these modules until the issue is resolved.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2003-0542
RHSA-2004:015

Affected Products

Apache
Apache Http Server