CVE-2002-1593Apache Http Server vulnerability

5 documents5 sources
Severity
5.0MEDIUMNVD
EPSS
39.0%
top 2.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 25
Latest updateApr 30

Description

mod_dav in Apache before 2.0.42 does not properly handle versioning hooks, which may allow remote attackers to kill a child process via a null dereference and cause a denial of service (CPU consumption) in a preforked multi-processing module.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDapache/http_server10 versions+9

Patches

🔴Vulnerability Details

3
GHSA
GHSA-xxjj-crx8-rwgg: mod_dav in Apache before 22022-04-30
CVEList
CVE-2002-1593: mod_dav in Apache before 22005-03-13
OSV
CVE-2002-1593: mod_dav in Apache before 22002-09-25

📋Vendor Advisories

1
Debian
CVE-2002-1593: apache2 - mod_dav in Apache before 2.0.42 does not properly handle versioning hooks, which...2002
CVE-2002-1593 — Apache Http Server vulnerability | cvebase