CVE-2003-0192Apache Http Server vulnerability

7 documents7 sources
Severity
6.4MEDIUMNVD
EPSS
11.8%
top 6.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 18
Latest updateMay 3

Description

Apache 2 before 2.0.47, and certain versions of mod_ssl for Apache 1.3, do not properly handle "certain sequences of per-directory renegotiations and the SSLCipherSuite directive being used to upgrade from a weak ciphersuite to a strong one," which could cause Apache to use the weak ciphersuite.

CVSS vector

AV:N/AC:L/C:N/I:P/A:PExploitability: 10.0 | Impact: 4.9

Affected Packages1 packages

NVDapache/http_server15 versions+14

Patches

🔴Vulnerability Details

3
GHSA
GHSA-6r62-6x7v-wrm2: Apache 2 before 22022-05-03
OSV
CVE-2003-0192: Apache 2 before 22003-08-18
CVEList
CVE-2003-0192: Apache 2 before 22003-07-10

📋Vendor Advisories

2
Red Hat
security flaw2003-07-09
Debian
CVE-2003-0192: apache2 - Apache 2 before 2.0.47, and certain versions of mod_ssl for Apache 1.3, do not p...2003

💬Community

1
Bugzilla
CVE-2003-0192 security flaw2018-08-16
CVE-2003-0192 — Apache Http Server vulnerability | cvebase