Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrary code as the apache user via SSI (XSSI) documents that trigger a length calculation error.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Httpd | — | Upgrade to the latest version of Apache HTTPD | Apr 12, 2012 | Feb 9, 2005 |
| Freebsd | — | Upgrade ru-apacheUpgrade apache+sslUpgrade apache+mod_ssl+ipv6Upgrade apacheUpgrade ru-apache+mod_sslUpgrade apache+mod_perlUpgrade apache+ipv6Upgrade apache+mod_ssl | Dec 10, 2025 | Nov 6, 2004 |
| Gentoo Linux | — | Upgrade www-servers/apache. | Oct 30, 2017 | Feb 9, 2005 |
| Suse | — | Upgrade apacheUpgrade mod_ssl | Feb 17, 2015 | Feb 9, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub