CVE-2002-0843
Buffer overflows in the ApacheBench benchmark support program (ab.c) in Apache before 1.3.27, and Apache 2.x before 2.0.43, allow a malicious web server to cause a denial of service and possibly execute arbitrary code via a long response.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 21.4%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Buffer overflows in the ApacheBench benchmark support program (ab.c) in Apache before 1.3.27, and Apache 2.x before 2.0.43, allow a malicious web server to cause a denial of service and possibly execute arbitrary code via a long response.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 21.42% probability · 97th percentile
- CISA KEV
- Not listed
- Affected
- apache/http server · oracle/application server · oracle/database server · oracle/oracle8i
- Source
- cve@mitre.org
References
- ftp://patches.sgi.com/support/free/security/advisories/20021105-01-I
- http://archives.neohapsis.com/archives/bugtraq/2002-10/0229.html
- http://archives.neohapsis.com/archives/bugtraq/2002-10/0254.html
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000530
- http://distro.conectiva.com/atualizacoes/?id=a&anuncio=000530
- http://marc.info/?l=apache-httpd-announce&m=103367938230488&w=2
- http://marc.info/?l=bugtraq&m=103376585508776&w=2
- http://online.securityfocus.com/advisories/4617
- http://secunia.com/advisories/21425
- http://www-1.ibm.com/support/search.wss?rs=0&q=IY87070&apar=only
- http://www.apacheweek.com/issues/02-10-04Vendor Advisory
- http://www.debian.org/security/2002/dsa-187
- http://www.debian.org/security/2002/dsa-188
- http://www.debian.org/security/2002/dsa-195
- http://www.iss.net/security_center/static/10281.php
- http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-068.php
- http://www.linuxsecurity.com/advisories/other_advisory-2414.html
- http://www.securityfocus.com/bid/5887
- http://www.securityfocus.com/bid/5995
- http://www.securityfocus.com/bid/5996
- http://www.vupen.com/english/advisories/2006/3263
- http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=2871
- https://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/rd00b45b93fda4a5bd013b28587207d0e00f99f6e3308dbb6025f3b01%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/rf2f0f3611f937cf6cfb3b4fe4a67f69885855126110e1e3f2fb2728e%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E
- ftp://patches.sgi.com/support/free/security/advisories/20021105-01-I
- http://archives.neohapsis.com/archives/bugtraq/2002-10/0229.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.