Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2003-0993 | First vendor Publication | 2004-03-29 |
Vendor | Cve | Last vendor Modification | 2024-11-20 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 7.5 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
mod_access in Apache 1.3 before 1.3.30, when running big-endian 64-bit platforms, does not properly parse Allow/Deny rules using IP addresses without a netmask, which could allow remote attackers to bypass intended access restrictions. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0993 |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:100111 | |||
Oval ID: | oval:org.mitre.oval:def:100111 | ||
Title: | Apache Allow/Deny Parsing Error | ||
Description: | mod_access in Apache 1.3 before 1.3.30, when running big-endian 64-bit platforms, does not properly parse Allow/Deny rules using IP addresses without a netmask, which could allow remote attackers to bypass intended access restrictions. | ||
Family: | unix | Class: | vulnerability |
Reference(s): | CVE-2003-0993 | Version: | 1 |
Platform(s): | Sun Solaris 8 Sun Solaris 9 | Product(s): | Apache |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:4670 | |||
Oval ID: | oval:org.mitre.oval:def:4670 | ||
Title: | Apache Mod_Access Access Control Rule Bypass Vulnerability | ||
Description: | mod_access in Apache 1.3 before 1.3.30, when running big-endian 64-bit platforms, does not properly parse Allow/Deny rules using IP addresses without a netmask, which could allow remote attackers to bypass intended access restrictions. | ||
Family: | unix | Class: | vulnerability |
Reference(s): | CVE-2003-0993 | Version: | 1 |
Platform(s): | Sun Solaris 8 Sun Solaris 9 | Product(s): | Apache |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2008-09-24 | Name : Gentoo Security Advisory GLSA 200405-22 (Apache) File : nvt/glsa_200405_22.nasl |
2008-09-04 | Name : FreeBSD Ports: apache File : nvt/freebsd_apache7.nasl |
2005-11-03 | Name : Apache mod_access rule bypass File : nvt/apache_access_wo_netmask.nasl |
0000-00-00 | Name : Slackware Advisory SSA:2004-133-01 apache File : nvt/esoft_slk_ssa_2004_133_01.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
4181 | Apache HTTP Server mod_access IP Address Netmask Rule Bypass Apache Web Server contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when mod_access is used to restrict access to files and directories and a subnet mask is not specified when setting IP addresses to allow or deny, which may cause the server to incorrectly evaluate the IP address. This flaw may allow an attacker to gain unauthorized access to files and/or directories. |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2005-07-13 | Name : The remote Slackware host is missing a security update. File : Slackware_SSA_2004-133-01.nasl - Type : ACT_GATHER_INFO |
2005-07-13 | Name : The remote FreeBSD host is missing one or more security-related updates. File : freebsd_pkg_09d418db70fd11d8873f0020ed76ef5a.nasl - Type : ACT_GATHER_INFO |
2004-10-17 | Name : The remote host is missing Sun Security Patch number 116973-07 File : solaris8_116973.nasl - Type : ACT_GATHER_INFO |
2004-10-17 | Name : The remote host is missing Sun Security Patch number 116974-07 File : solaris8_x86_116974.nasl - Type : ACT_GATHER_INFO |
2004-08-30 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-200405-22.nasl - Type : ACT_GATHER_INFO |
2004-07-31 | Name : The remote web server is affected by an access control bypass vulnerability. File : apache_access_wo_netmask.nasl - Type : ACT_GATHER_INFO |
2004-07-31 | Name : The remote Mandrake Linux host is missing one or more security updates. File : mandrake_MDKSA-2004-046.nasl - Type : ACT_GATHER_INFO |
2004-07-12 | Name : The remote host is missing Sun Security Patch number 113146-13 File : solaris9_113146.nasl - Type : ACT_GATHER_INFO |
2004-07-12 | Name : The remote host is missing Sun Security Patch number 114145-12 File : solaris9_x86_114145.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:23:07 |
|
2024-11-28 12:05:48 |
|
2023-11-07 21:48:10 |
|
2021-06-06 17:23:04 |
|
2021-06-03 13:23:14 |
|
2021-05-04 12:02:13 |
|
2021-04-22 01:02:22 |
|
2021-03-30 17:22:46 |
|
2020-05-23 00:15:33 |
|
2017-10-10 09:23:25 |
|
2016-10-18 12:01:14 |
|
2016-04-26 12:39:10 |
|
2014-02-17 10:26:45 |
|
2013-05-11 11:53:24 |
|