Apache 2.0.x < 2.0.48 Multiple Vulnerabilities (OF, Info Disc.)

critical Nessus Plugin ID 11853

Synopsis

The remote web server is affected by multiple vulnerabilities.

Description

The remote host appears to be running a version of Apache 2.0.x prior to 2.0.48. It is, therefore, affected by multiple vulnerabilities :

- The mod_rewrite and mod_alias modules fail to handle regular expressions containing more than 9 captures resulting in a buffer overflow.

- A vulnerability may occur in the mod_cgid module caused by the mishandling of CGI redirect paths. This could cause Apache to send the output of a CGI program to the wrong client.

Solution

Upgrade to Apache web server version 2.0.48 or later.

See Also

https://www.securityfocus.com/archive/1/342674/30/0/threaded

https://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html

Plugin Details

Severity: Critical

ID: 11853

File Name: apache_2_0_48.nasl

Version: 1.33

Type: remote

Family: Web Servers

Published: 9/26/2003

Updated: 11/15/2018

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Temporal Vector: E:U/RL:OF/RC:C

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:apache:http_server

Required KB Items: installed_sw/Apache

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 10/29/2003

Reference Information

CVE: CVE-2003-0789, CVE-2003-0542

BID: 8926

Secunia: 10096, 10845, 17311

CWE: 119