CVE-2002-0839Apache Http Server vulnerability

5 documents5 sources
Severity
7.2HIGHNVD
EPSS
0.1%
top 65.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 11
Latest updateMay 3

Description

The shared memory scoreboard in the HTTP daemon for Apache 1.3.x before 1.3.27 allows any user running as the Apache UID to send a SIGUSR1 signal to any process as root, resulting in a denial of service (process kill) or possibly other behaviors that would not normally be allowed, by modifying the parent[].pid and parent[].last_rtime segments in the scoreboard.

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages1 packages

NVDapache/http_server1.3.01.3.27

Also affects: Debian Linux 2.2, 3.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-6hh5-x52p-p482: The shared memory scoreboard in the HTTP daemon for Apache 12022-05-03
CVEList
CVE-2002-0839: The shared memory scoreboard in the HTTP daemon for Apache 12002-10-05

📋Vendor Advisories

1
Red Hat
security flaw2002-10-03

💬Community

1
Bugzilla
CVE-2002-0839 security flaw2018-08-16
CVE-2002-0839 — Apache Http Server vulnerability | cvebase