CVE-2001-1342: Medium severity Apache HTTP Server vulnerability
Published May 12, 2001
·Updated
Apache before 1.3.20 on Windows and OS/2 systems allows remote attackers to cause a denial of service (GPF) via an HTTP request for a URI that contains a large number of / (slash) or other characters, which causes certain functions to dereference a null pointer.
Affected Software
7 affected components
Apache HTTP Server=1.3.12
Apache HTTP Server=1.3.14
Apache HTTP Server=1.3.15
Apache HTTP Server=1.3.16
Apache HTTP Server=1.3.17
Apache HTTP Server=1.3.18
Apache HTTP Server=1.3.19
Remediation
Patch Available
Event History
May 12, 2001
CVE Published
04:00 AM
Jun 25, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-1342?
CVE-2001-1342 has been classified as a denial of service vulnerability.
2
How do I fix CVE-2001-1342?
To fix CVE-2001-1342, upgrade Apache HTTP Server to version 1.3.20 or later.
3
What systems are affected by CVE-2001-1342?
CVE-2001-1342 affects Apache HTTP Server versions prior to 1.3.20 on Windows and OS/2 systems.
4
What type of attacks does CVE-2001-1342 enable?
CVE-2001-1342 enables remote attackers to cause a denial of service by sending specially crafted HTTP requests.
5
What consequences arise from CVE-2001-1342 exploitation?
Exploitation of CVE-2001-1342 can lead to server crashes due to null pointer dereference.