PT-2003-1909 · Apache · Mod Gzip

Matthew Murphy

·

Published

2003-10-09

·

Updated

2016-10-18

·

CVE-2003-0842

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions mod gzip versions 1.3.26.1a and earlier
Description The issue is a stack-based buffer overflow in the mod gzip printf function for mod gzip when running in debug mode. This allows remote attackers to execute arbitrary code via a long filename in a GET request with an "Accept-Encoding: gzip" header.
Recommendations For mod gzip versions 1.3.26.1a and earlier, consider disabling the mod gzip module or restricting access to it until a fix is available. As a temporary workaround, avoid using the debug mode in mod gzip to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2003-0842

Affected Products

Mod Gzip