CVE-2003-0542
high · 7.2Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures.
7.2
CVSS
30.4%
EPSS (exploit prob.)
98th
EPSS percentile
2003-11-03
Published
AV:L/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apache | http_server | 1.3 |
| apache | http_server | 1.3.1 |
| apache | http_server | 1.3.3 |
| apache | http_server | 1.3.4 |
| apache | http_server | 1.3.6 |
| apache | http_server | 1.3.9 |
| apache | http_server | 1.3.11 |
| apache | http_server | 1.3.12 |
| apache | http_server | 1.3.14 |
| apache | http_server | 1.3.17 |
| apache | http_server | 1.3.18 |
| apache | http_server | 1.3.19 |
| apache | http_server | 1.3.20 |
| apache | http_server | 1.3.22 |
| apache | http_server | 1.3.23 |
| apache | http_server | 1.3.24 |
| apache | http_server | 1.3.25 |
| apache | http_server | 1.3.26 |
| apache | http_server | 1.3.27 |
| apache | http_server | 1.3.28 |
| apache | http_server | 2.0 |
| apache | http_server | 2.0.28 |
| apache | http_server | 2.0.32 |
| apache | http_server | 2.0.35 |
| apache | http_server | 2.0.36 |
| apache | http_server | 2.0.37 |
| apache | http_server | 2.0.38 |
| apache | http_server | 2.0.39 |
| apache | http_server | 2.0.40 |
| apache | http_server | 2.0.41 |
| apache | http_server | 2.0.42 |
| apache | http_server | 2.0.43 |
| apache | http_server | 2.0.44 |
| apache | http_server | 2.0.45 |
| apache | http_server | 2.0.46 |
| apache | http_server | 2.0.47 |
Check a specific version with /api/v1/cve/match.
References
- ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.6/SCOSA-2004.6.txt
- ftp://patches.sgi.com/support/free/security/advisories/20031203-01-U.asc
- ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc
- http://docs.info.apple.com/article.html?artnum=61798
- http://httpd.apache.org/dist/httpd/Announcement2.html
- http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html
- http://lists.apple.com/mhonarc/security-announce/msg00045.html
- http://marc.info/?l=bugtraq&m=106761802305141&w=2
- http://marc.info/?l=bugtraq&m=130497311408250&w=2
- http://secunia.com/advisories/10096
- http://secunia.com/advisories/10098
- http://secunia.com/advisories/10102
- http://secunia.com/advisories/10112
- http://secunia.com/advisories/10114
- http://secunia.com/advisories/10153
- http://secunia.com/advisories/10260
- http://secunia.com/advisories/10264
- http://secunia.com/advisories/10463
- http://secunia.com/advisories/10580
- http://secunia.com/advisories/10593
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-101444-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-101841-1
- http://www.kb.cert.org/vuls/id/434566
- http://www.kb.cert.org/vuls/id/549142
- http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:103
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2003-0542