CVE-2002-0842: High severity Oracle Application Server vulnerability
Format string vulnerability in certain third party modifications to moddav for logging bad gateway messages (e.g. Oracle9i Application Server 9.0.2) allows remote attackers to execute arbitrary code via a destination URI that forces a "502 Bad Gateway" response, which causes the format string specifiers to be returned from davlookupuri() in moddav.c, which is then used in a call to aplogrerror().
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-0842?
CVE-2002-0842 is classified as a critical vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2002-0842?
To fix CVE-2002-0842, it is recommended to upgrade to a patched version of Oracle Application Server that addresses the vulnerability.
What software is affected by CVE-2002-0842?
CVE-2002-0842 specifically affects Oracle Application Server version 9.0.2 among other third party modifications to mod_dav.
Can CVE-2002-0842 be exploited remotely?
Yes, CVE-2002-0842 can be exploited remotely by sending a specially crafted URI that triggers a format string vulnerability.
What are the potential impacts of exploiting CVE-2002-0842?
Exploiting CVE-2002-0842 could allow attackers to execute arbitrary code on affected systems, leading to a complete compromise.