Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2003-0132Missing Release of Resource after Effective Lifetime in Apache Http Server

Severity
5.0MEDIUMNVD
EPSS
85.0%
top 0.64%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedApr 11
Latest updateApr 29

Description

A memory leak in Apache 2.0 through 2.0.44 allows remote attackers to cause a denial of service (memory consumption) via large chunks of linefeed characters, which causes Apache to allocate 80 bytes for each linefeed.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDapache/http_server2.0.02.0.44

🔴Vulnerability Details

3
GHSA
GHSA-g3vc-c43j-gjjv: A memory leak in Apache 22022-04-29
OSV
CVE-2003-0132: A memory leak in Apache 22003-04-11
CVEList
CVE-2003-0132: A memory leak in Apache 22003-04-03

💥Exploits & PoCs

2
Exploit-DB
Apache 2.0.44 (Linux) - Remote Denial of Service2003-04-11
Exploit-DB
Apache 2.x - Memory Leak2003-04-09

📋Vendor Advisories

2
Red Hat
security flaw2003-04-02
Debian
CVE-2003-0132: apache2 - A memory leak in Apache 2.0 through 2.0.44 allows remote attackers to cause a de...2003

💬Community

1
Bugzilla
CVE-2003-0132 security flaw2018-08-16
CVE-2003-0132 — Apache Http Server vulnerability | cvebase