SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2003-0542

Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9…

HIGH 7.2EPSS 30.4%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 30.4%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.

Description

Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures.

CVSS 2.0
7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
EPSS
30.43% probability · 98th percentile
CISA KEV
Not listed
Weakness
CWE-119
Affected
apache/http server
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.