Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures.
CVSS Details
- CVSS 3.1 Base Score: 8.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Httpd | — | Upgrade to the latest version of Apache HTTPD | Apr 12, 2012 | Nov 3, 2003 |
| Apache Httpd 1_3_x Local Configuration Regular Expression Overflow | — | — | Aug 16, 2010 | Nov 3, 2003 |
| Debian | — | Upgrade apache2 | Jul 30, 2024 | Nov 3, 2003 |
| Gentoo Linux | — | Upgrade www-servers/apache. | Oct 30, 2017 | Nov 3, 2003 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub