CVE-2002-0843: Buffer Overflow
Published Oct 5, 2002
·Updated
Buffer overflows in the ApacheBench benchmark support program (ab.c) in Apache before 1.3.27, and Apache 2.x before 2.0.43, allow a malicious web server to cause a denial of service and possibly execute arbitrary code via a long response.
Affected Software
30 affected components
Apache HTTP Server=1.3
Apache HTTP Server=1.3.1
Apache HTTP Server=1.3.3
Apache HTTP Server=1.3.4
Apache HTTP Server=1.3.6
Apache HTTP Server=1.3.9
Apache HTTP Server=1.3.11
Apache HTTP Server=1.3.12
Apache HTTP Server=1.3.14
Apache HTTP Server=1.3.17
Apache HTTP Server=1.3.18
Apache HTTP Server=1.3.19
Apache HTTP Server=1.3.20
Apache HTTP Server=1.3.22
Apache HTTP Server=1.3.23
Apache HTTP Server=1.3.24
Apache HTTP Server=1.3.25
Apache HTTP Server=1.3.26
Oracle Application Server=1.0.2
Oracle Application Server=1.0.2.1s
Oracle Application Server=1.0.2.2
Oracle Application Server=9.0.2
Oracle Application Server=9.0.2-r2
Oracle Application Server=9.0.2.1
Oracle Database Server=8.1.7
Oracle Database Server=9.2.2
Oracle Oracle8i=8.1.7
Oracle Oracle8i=8.1.7.0.0_enterprise
Oracle Oracle8i=8.1.7.1
Oracle Oracle8i=8.1.7.1.0_enterprise
Event History
Oct 5, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0843?
CVE-2002-0843 is classified as a high-severity vulnerability as it could lead to denial of service and arbitrary code execution.
2
How do I fix CVE-2002-0843?
To fix CVE-2002-0843, upgrade to Apache HTTP Server version 1.3.27 or later, or 2.0.43 or later.
3
What types of systems are affected by CVE-2002-0843?
CVE-2002-0843 affects specific versions of Apache HTTP Server and Oracle Application Server.
4
What is the nature of the vulnerability in CVE-2002-0843?
CVE-2002-0843 is a buffer overflow vulnerability that is exploited through long responses from a web server.
5
Can CVE-2002-0843 be exploited remotely?
Yes, CVE-2002-0843 can be exploited remotely by a malicious web server.