cbcvebase.
CVE-2002-0392
published 2002-07-03

CVE-2002-0392: Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a…

PriorityP181high7.5CVSS 2.0
AVNACLAuNCPIPAP
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
95.03%
99.9th percentile
Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a chunk-encoded HTTP request that causes Apache to use an incorrect size.

Affected

4 ranges
VendorProductVersion rangeFixed in
apachehttp_server1.2.2 – 1.3.24
apachehttp_server2.0.0 – 2.0.36
debianapache2< apache2 2.0.37 (bookworm)apache2 2.0.37 (bookworm)
debiandebian_linux

Detection & IOCsextracted from sources · hover to see the quote

commandTransfer-Encoding: CHUNKED (HTTP header used to trigger integer wrap vulnerability)
bytes
FFFFFFF0 (chunk size integer wrap value in Transfer-Encoding: CHUNKED request)
  • Detect HTTP requests with Transfer-Encoding: CHUNKED header containing an oversized/wrapping chunk size value such as FFFFFFF0, which triggers the integer wrap in Apache 1.2.x–1.3.24 and 2.0–2.0.36.
  • The Metasploit module targets Windows x86 Apache builds; exploitation results in privileged code execution. Alert on unexpected child process spawning from Apache (httpd.exe) on Windows systems running affected versions.
  • ·The exploit module requires use of the Check() function to determine the exact target version before launching; using the wrong target against Oracle 8.1.7 bundled Apache will crash the server without restart.
  • ·The vulnerability affects Apache 1.2.x through 1.3.24 and Apache 2.0 through 2.0.36; the module was specifically tested against official Win32 builds 1.3.9–1.3.24 and also targets co-branded versions (Oracle 8i/9i, IBM HTTPD).

CVSS provenance

nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vulncheck7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.