CVE-1999-1293: Critical severity Apache HTTP Server vulnerability

Published Dec 31, 1999
·
Updated

modproxy in Apache 1.2.5 and earlier allows remote attackers to cause a denial of service via malformed FTP commands, which causes Apache to dump core.

Affected Software

1 affected component
Apache HTTP Server<=1.2.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove Apache Http Server (mod_proxy) from your environment.

    Uninstall or remove the mod_proxy module from the server if proxy functionality is not required.

  2. Configuration

    If running Apache 1.2.5 or earlier, disable the mod_proxy module (and mod_proxy_ftp if present) in the Apache configuration to prevent processing of FTP commands.

    Apache Http Server (mod_proxy) module enabled = disabled
  3. Compensating control

    Block or restrict access to FTP proxy endpoints and related ports (for example, port 21) at network perimeter firewalls or inline filters to prevent external attackers from sending malformed FTP commands to Apache.

  4. Operational

    Restart the Apache service after disabling or removing mod_proxy to ensure the configuration change takes effect.

Event History

Dec 31, 1999
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityAffected Software
Sep 12, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-1293?

CVE-1999-1293 is classified as a denial of service vulnerability.

2

How do I fix CVE-1999-1293?

To fix CVE-1999-1293, upgrade Apache HTTP Server to version 1.3 or later.

3

What versions of Apache are affected by CVE-1999-1293?

CVE-1999-1293 affects Apache HTTP Server version 1.2.5 and earlier.

4

Can CVE-1999-1293 be exploited remotely?

Yes, CVE-1999-1293 can be exploited remotely through malformed FTP commands.

5

What impact does CVE-1999-1293 have on my server?

CVE-1999-1293 can cause your server to crash and produce a core dump.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203