First published: Tue Dec 19 2000(Updated: )
mod_rewrite in Apache 1.3.12 and earlier allows remote attackers to read arbitrary files if a RewriteRule directive is expanded to include a filename whose name contains a regular expression.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Http Server | =1.0.5 | |
Apache Http Server | =0.8.11 | |
Apache Http Server | =1.1.1 | |
Apache Http Server | =1.3.11 | |
Apache Http Server | =1.0.2 | |
Apache Http Server | =1.1 | |
Apache Http Server | =1.0 | |
Apache Http Server | =1.0.3 | |
Apache Http Server | =1.3.12 | |
Apache Http Server | =0.8.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0913 is considered a high severity vulnerability due to its ability to allow remote attackers to read arbitrary files.
To fix CVE-2000-0913, update Apache to a version later than 1.3.12 that does not contain this vulnerability.
CVE-2000-0913 affects Apache 1.3.12 and earlier versions, including 1.0.5, 1.1.1, and various other versions.
Yes, the exploitation of CVE-2000-0913 can lead to significant data leakage, as attackers can read arbitrary files from the server.
A possible workaround for CVE-2000-0913 is to disable mod_rewrite or restrict its use to a safe configuration until an update can be applied.