Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2003-0542 | First vendor Publication | 2003-11-03 |
Vendor | Cve | Last vendor Modification | 2024-11-20 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:L/AC:L/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 7.2 | Attack Range | Local |
Cvss Impact Score | 10 | Attack Complexity | Low |
Cvss Expoit Score | 3.9 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0542 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:3799 | |||
Oval ID: | oval:org.mitre.oval:def:3799 | ||
Title: | Apache Web Server Multiple Module Local Buffer Overflow | ||
Description: | Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures. | ||
Family: | unix | Class: | vulnerability |
Reference(s): | CVE-2003-0542 | Version: | 1 |
Platform(s): | Sun Solaris 8 Sun Solaris 9 | Product(s): | Apache |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:863 | |||
Oval ID: | oval:org.mitre.oval:def:863 | ||
Title: | Red Hat Multiple stack-based BO Vulnerabilities in Apache | ||
Description: | Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures. | ||
Family: | unix | Class: | vulnerability |
Reference(s): | CVE-2003-0542 | Version: | 4 |
Platform(s): | Red Hat Linux 9 | Product(s): | httpd |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:864 | |||
Oval ID: | oval:org.mitre.oval:def:864 | ||
Title: | Red Hat Enterprise 3 Multiple stack-based BO Vulnerabilities in Apache | ||
Description: | Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures. | ||
Family: | unix | Class: | vulnerability |
Reference(s): | CVE-2003-0542 | Version: | 4 |
Platform(s): | Red Hat Enterprise Linux 3 | Product(s): | Apache |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:9458 | |||
Oval ID: | oval:org.mitre.oval:def:9458 | ||
Title: | Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures. | ||
Description: | Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures. | ||
Family: | unix | Class: | vulnerability |
Reference(s): | CVE-2003-0542 | Version: | 5 |
Platform(s): | Red Hat Enterprise Linux 3 CentOS Linux 3 | Product(s): | |
Definition Synopsis: | |||
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2009-05-05 | Name : HP-UX Update for Apache mod_cgid HPSBUX00301 File : nvt/gb_hp_ux_HPSBUX00301.nasl |
2008-09-24 | Name : Gentoo Security Advisory GLSA 200310-03 (Apache) File : nvt/glsa_200310_03.nasl |
2008-09-24 | Name : Gentoo Security Advisory GLSA 200310-04 (Apache) File : nvt/glsa_200310_04.nasl |
0000-00-00 | Name : Slackware Advisory SSA:2003-308-01 apache security update File : nvt/esoft_slk_ssa_2003_308_01.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
7611 | Apache HTTP Server mod_alias Local Overflow A local overflow exists in Apache. The mod_alias module fails to handle regular expressions containing more than 9 captures (stored strings matching a particular pattern) resulting in a buffer overflow. With a specially crafted request, an attacker can execute arbitrary code or cause a denial of service resulting in a loss of integrity and/or confidentiality. |
2733 | Apache HTTP Server mod_rewrite Local Overflow A local overflow exists in Apache. The mod_rewrite module fails to handle regular expressions containing more than 9 captures (stored strings matching a particular pattern) resulting in a buffer overflow. With a specially crafted request, an attacker can execute arbitrary code or cause a denial of service resulting in a loss of integrity and/or confidentiality. |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2005-07-13 | Name : The remote Slackware host is missing a security update. File : Slackware_SSA_2003-308-01.nasl - Type : ACT_GATHER_INFO |
2004-10-17 | Name : The remote host is missing Sun Security Patch number 116973-07 File : solaris8_116973.nasl - Type : ACT_GATHER_INFO |
2004-10-17 | Name : The remote host is missing Sun Security Patch number 116974-07 File : solaris8_x86_116974.nasl - Type : ACT_GATHER_INFO |
2004-07-31 | Name : The remote Mandrake Linux host is missing one or more security updates. File : mandrake_MDKSA-2003-103.nasl - Type : ACT_GATHER_INFO |
2004-07-23 | Name : The remote Fedora Core host is missing a security update. File : fedora_2003-004.nasl - Type : ACT_GATHER_INFO |
2004-07-12 | Name : The remote host is missing Sun Security Patch number 113146-13 File : solaris9_113146.nasl - Type : ACT_GATHER_INFO |
2004-07-12 | Name : The remote host is missing Sun Security Patch number 114145-12 File : solaris9_x86_114145.nasl - Type : ACT_GATHER_INFO |
2004-07-06 | Name : The remote host is missing a Mac OS X security update. File : macosx_SecUpd20040126.nasl - Type : ACT_GATHER_INFO |
2004-07-06 | Name : The remote host is using an unsupported version of Mac OS X. File : macosx_version.nasl - Type : ACT_GATHER_INFO |
2004-07-06 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2003-360.nasl - Type : ACT_GATHER_INFO |
2004-07-06 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2004-015.nasl - Type : ACT_GATHER_INFO |
2003-11-01 | Name : The remote web server is affected by multiple local buffer overflow vulnerabi... File : apache_1_3_29.nasl - Type : ACT_GATHER_INFO |
2003-09-26 | Name : The remote web server is affected by multiple vulnerabilities. File : apache_2_0_48.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:23:20 |
|
2024-11-28 12:05:39 |
|
2023-11-07 21:48:10 |
|
2021-06-06 17:23:04 |
|
2021-05-04 12:02:09 |
|
2021-04-22 01:02:22 |
|
2021-03-30 17:22:45 |
|
2020-05-23 00:15:26 |
|
2019-08-20 12:00:47 |
|
2019-03-18 12:00:56 |
|
2018-05-03 09:19:25 |
|
2017-07-11 12:01:17 |
|
2016-10-18 12:01:12 |
|
2016-04-26 12:35:01 |
|
2014-02-17 10:26:22 |
|
2013-07-18 17:18:46 |
|
2013-05-11 11:51:45 |
|