VulnerabilityModified
CVE-2003-0020
Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences.
MEDIUM 5.0EPSS 16.5%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 16.5%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 16.46% probability · 97th percentile
- CISA KEV
- Not listed
- Affected
- apache/http server
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.htmlBroken Link
- http://frontal2.mandriva.com/security/advisories?name=MDKSA-2004:046Third Party Advisory
- http://marc.info/?l=bugtraq&m=104612710031920&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=108369640424244&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=108437852004207&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=108731648532365&w=2Third Party Advisory
- http://security.gentoo.org/glsa/glsa-200405-22.xmlThird Party Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-101555-1Broken Link
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-57628-1Broken Link
- http://www.iss.net/security_center/static/11412.phpBroken Link
- http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:050Broken Link
- http://www.redhat.com/support/errata/RHSA-2003-082.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2003-083.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2003-104.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2003-139.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2003-243.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2003-244.htmlThird Party Advisory
- http://www.securityfocus.com/bid/9930Third Party Advisory, VDB Entry
- http://www.slackware.com/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.529643Mailing List, Third Party Advisory
- http://www.trustix.org/errata/2004/0017Broken Link
- http://www.trustix.org/errata/2004/0027Broken Link
- https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/r5001ecf3d6b2bdd0b732e527654248abb264f08390045d30709a92f6%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/r7035b7c9091c4b665a3b7205364775410646f12125d48e74e395f2ce%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.