CVE-2002-0392
high · 7.5Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a chunk-encoded HTTP request that causes Apache to use an incorrect size.
7.5
CVSS
95.0%
EPSS (exploit prob.)
100th
EPSS percentile
2002-07-03
Published
AV:N/AC:L/Au:N/C:P/I:P/A:P
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apache | http_server | >= 1.2.2, <= 1.3.24 |
| apache | http_server | >= 2.0.0, <= 2.0.36 |
| debian | debian_linux | 2.2 |
Check a specific version with /api/v1/cve/match.
References
- ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-029.0.txt
- ftp://ftp.caldera.com/pub/updates/OpenServer/CSSA-2002-SCO.32
- ftp://ftp.caldera.com/pub/updates/OpenUNIX/CSSA-2002-SCO.31
- ftp://patches.sgi.com/support/free/security/advisories/20020605-01-A
- ftp://patches.sgi.com/support/free/security/advisories/20020605-01-I
- http://archives.neohapsis.com/archives/bugtraq/2002-06/0235.html
- http://archives.neohapsis.com/archives/bugtraq/2002-06/0266.html
- http://distro.conectiva.com/atualizacoes/?id=a&anuncio=000498
- http://frontal2.mandriva.com/security/advisories?name=MDKSA-2002:039
- http://httpd.apache.org/info/security_bulletin_20020617.txt
- http://online.securityfocus.com/advisories/4240
- http://online.securityfocus.com/advisories/4257
- http://online.securityfocus.com/archive/1/278149
- http://rhn.redhat.com/errata/RHSA-2002-103.html
- http://rhn.redhat.com/errata/RHSA-2002-117.html
- http://rhn.redhat.com/errata/RHSA-2002-118.html
- http://secunia.com/advisories/21917
- http://www.cert.org/advisories/CA-2002-17.html
- http://www.debian.org/security/2002/dsa-131
- http://www.debian.org/security/2002/dsa-132
- http://www.debian.org/security/2002/dsa-133
- http://www.frsirt.com/english/advisories/2006/3598
- http://www.iss.net/security_center/static/9249.php
- http://www.kb.cert.org/vuls/id/944335
- http://www.linuxsecurity.com/advisories/other_advisory-2137.html
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2002-0392