CVE-2003-0020
published 2003-03-18CVE-2003-0020: Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal…
PriorityP422medium5CVSS 2.0
AVNACLAuNCNIPAN
EXPLOIT
EPSS
10.87%
95.4th percentile
Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | >= 1.3.0 < 1.3.26 | 1.3.26 |
| apache | http_server | >= 1.3.0 < 1.3.31 | 1.3.31 |
| apache | http_server | >= 2.0.0 < 2.0.46 | 2.0.46 |
| apache | http_server | >= 2.0.0 < 2.0.49 | 2.0.49 |
| debian | apache2 | < apache2 2.0.46 (bookworm) | apache2 2.0.46 (bookworm) |
| debian | apache2 | < apache2 2.0.49 (bookworm) | apache2 2.0.49 (bookworm) |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
security flaw
vendor_redhat·2003-02-24·CVSS 5.0
CVE-2003-0020 [MEDIUM] security flaw
security flaw
Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences.
Red Hat
security flaw
vendor_redhat·2003-02-24·CVSS 5.0
CVE-2003-0083 [MEDIUM] security flaw
security flaw
Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter terminal escape sequences from its access logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences, a different vulnerability than CVE-2003-0020.
Debian
CVE-2003-0083: apache2 - Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter te...
vendor_debian·2003·CVSS 5.0
CVE-2003-0083 [MEDIUM] CVE-2003-0083: apache2 - Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter te...
Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter terminal escape sequences from its access logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences, a different vulnerability than CVE-2003-0020.
Scope: local
bookworm: resolved (fixed in 2.0.46)
bullseye: resolved (fixed in 2.0.46)
forky: resolved (fixed in 2.0.46)
sid: resolved (fixed in 2.0.46)
trixie: resolved (fixed in 2.0.46)
Debian
CVE-2003-0020: apache2 - Apache does not filter terminal escape sequences from its error logs, which coul...
vendor_debian·2003·CVSS 5.0
CVE-2003-0020 [MEDIUM] CVE-2003-0020: apache2 - Apache does not filter terminal escape sequences from its error logs, which coul...
Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences.
Scope: local
bookworm: resolved (fixed in 2.0.49)
bullseye: resolved (fixed in 2.0.49)
forky: resolved (fixed in 2.0.49)
sid: resolved (fixed in 2.0.49)
trixie: resolved (fixed in 2.0.49)
Red Hat
httpd: log files contain information directly supplied by clients and does not filter or quote control characters
vendor_redhat·2001-12-31·CVSS 5.0
CVE-2001-1556 [MEDIUM] CWE-532 httpd: log files contain information directly supplied by clients and does not filter or quote control characters
httpd: log files contain information directly supplied by clients and does not filter or quote control characters
The log files in Apache web server contain information directly supplied by clients and does not filter or quote control characters, which could allow remote attackers to hide HTTP requests and spoof source IP addresses when logs are viewed with UNIX programs such as cat, tail, and grep.
Statement: This is a duplicate CVE name and is a combination of CVE-2003-0020 and CVE-2003-0083.
Package: httpd (Red Hat Enterprise Linux 5) - Not affected
Package: httpd (Red Hat Enterprise Linux 6) - Not affected
Package: httpd (Red Hat Enterprise Linux 7) - Not affected
Package: httpd:2.4/httpd (Red Hat Enterprise Linux 8) - Not affected
Package: httpd (Red Hat JBoss Core Services) -
GHSA
GHSA-cc5w-cgc4-9qf7: Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal
ghsa_unreviewed·2022-04-29
CVE-2003-0020 [MEDIUM] GHSA-cc5w-cgc4-9qf7: Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal
Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences.
GHSA
GHSA-cvpf-93m7-95jr: Apache 1
ghsa_unreviewed·2022-04-29·CVSS 5.0
CVE-2003-0083 [MEDIUM] GHSA-cvpf-93m7-95jr: Apache 1
Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter terminal escape sequences from its access logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences, a different vulnerability than CVE-2003-0020.
OSV
CVE-2003-0083: Apache 1
osv·2003-04-02·CVSS 5.0
CVE-2003-0083 [MEDIUM] CVE-2003-0083: Apache 1
Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter terminal escape sequences from its access logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences, a different vulnerability than CVE-2003-0020.
OSV
CVE-2003-0020: Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal
osv·2003-03-18·CVSS 5.0
CVE-2003-0020 [MEDIUM] CVE-2003-0020: Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal
Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences.
No detection rules found.
Bugzilla
CVE-2003-0083 security flaw
bugzilla·2018-08-16·CVSS 5.0
CVE-2003-0083 [MEDIUM] CVE-2003-0083 security flaw
CVE-2003-0083 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter terminal escape sequences from its access logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences, a different vulnerability than CVE-2003-0020.
Bugzilla
CVE-2003-0020 security flaw
bugzilla·2018-08-16·CVSS 5.0
CVE-2003-0020 [MEDIUM] CVE-2003-0020 security flaw
CVE-2003-0020 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences.
CWE
Improper Neutralization of Escape, Meta, or Control Sequences
mitre_cwe
CWE-150 Improper Neutralization of Escape, Meta, or Control Sequences
CWE-150: Improper Neutralization of Escape, Meta, or Control Sequences
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as escape, meta, or control character sequences when they are sent to a downstream component.
As data is parsed, an injected/absent/malformed delimiter may cause the process to take unexpected actions.
Modes of Introduction:
Phase: Implementation
Note: REALIZATION: This weakness is caused during implementation of an architectural security tactic.
Common Consequences:
Scope: Integrity. Impact: Unexpected State.
Detection Methods:
Automated Static Analysis: Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some ins
CWE
Improper Neutralization of Special Elements
mitre_cwe
CWE-138 Improper Neutralization of Special Elements
CWE-138: Improper Neutralization of Special Elements
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as control elements or syntactic markers when they are sent to a downstream component.
Most languages and protocols have their own special elements such as characters and reserved words. These special elements can carry control implications. If product does not prevent external control or influence over the inclusion of such special elements, the control flow of the program may be altered from what was intended. For example, both Unix and Windows interpret the symbol < ("less than") as meaning "read input from a file".
Modes of Introduction:
Phase: Implementation
Note: REALIZATION: Thi
http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.htmlhttp://frontal2.mandriva.com/security/advisories?name=MDKSA-2004:046http://marc.info/?l=bugtraq&m=104612710031920&w=2http://marc.info/?l=bugtraq&m=108369640424244&w=2http://marc.info/?l=bugtraq&m=108437852004207&w=2http://marc.info/?l=bugtraq&m=108731648532365&w=2http://security.gentoo.org/glsa/glsa-200405-22.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-26-101555-1http://sunsolve.sun.com/search/document.do?assetkey=1-26-57628-1http://www.iss.net/security_center/static/11412.phphttp://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:050http://www.redhat.com/support/errata/RHSA-2003-082.htmlhttp://www.redhat.com/support/errata/RHSA-2003-083.htmlhttp://www.redhat.com/support/errata/RHSA-2003-104.htmlhttp://www.redhat.com/support/errata/RHSA-2003-139.htmlhttp://www.redhat.com/support/errata/RHSA-2003-243.htmlhttp://www.redhat.com/support/errata/RHSA-2003-244.htmlhttp://www.securityfocus.com/bid/9930http://www.slackware.com/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.529643http://www.trustix.org/errata/2004/0017http://www.trustix.org/errata/2004/0027https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r5001ecf3d6b2bdd0b732e527654248abb264f08390045d30709a92f6%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r7035b7c9091c4b665a3b7205364775410646f12125d48e74e395f2ce%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rd00b45b93fda4a5bd013b28587207d0e00f99f6e3308dbb6025f3b01%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/re028d61fe612b0908595d658b9b39e74bca56f2a1ed3c5f06b5ab571%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf2f0f3611f937cf6cfb3b4fe4a67f69885855126110e1e3f2fb2728e%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100109https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A150https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4114http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.htmlhttp://frontal2.mandriva.com/security/advisories?name=MDKSA-2004:046http://marc.info/?l=bugtraq&m=104612710031920&w=2http://marc.info/?l=bugtraq&m=108369640424244&w=2http://marc.info/?l=bugtraq&m=108437852004207&w=2http://marc.info/?l=bugtraq&m=108731648532365&w=2http://security.gentoo.org/glsa/glsa-200405-22.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-26-101555-1http://sunsolve.sun.com/search/document.do?assetkey=1-26-57628-1http://www.iss.net/security_center/static/11412.phphttp://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:050http://www.redhat.com/support/errata/RHSA-2003-082.htmlhttp://www.redhat.com/support/errata/RHSA-2003-083.htmlhttp://www.redhat.com/support/errata/RHSA-2003-104.htmlhttp://www.redhat.com/support/errata/RHSA-2003-139.htmlhttp://www.redhat.com/support/errata/RHSA-2003-243.htmlhttp://www.redhat.com/support/errata/RHSA-2003-244.htmlhttp://www.securityfocus.com/bid/9930http://www.slackware.com/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.529643http://www.trustix.org/errata/2004/0017http://www.trustix.org/errata/2004/0027https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r5001ecf3d6b2bdd0b732e527654248abb264f08390045d30709a92f6%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r7035b7c9091c4b665a3b7205364775410646f12125d48e74e395f2ce%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rd00b45b93fda4a5bd013b28587207d0e00f99f6e3308dbb6025f3b01%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/re028d61fe612b0908595d658b9b39e74bca56f2a1ed3c5f06b5ab571%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf2f0f3611f937cf6cfb3b4fe4a67f69885855126110e1e3f2fb2728e%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100109https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A150https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4114
2003-03-18
Published