First published: Mon May 06 2002(Updated: )
The ap_log_rerror function in Apache 2.0 through 2.035, when a CGI application encounters an error, sends error messages to the client that include the full path for the server, which allows remote attackers to obtain sensitive information.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache HTTP Server | =2.0 | |
Apache HTTP Server | =2.0.28 | |
Apache HTTP Server | =2.0.32 | |
Apache HTTP Server | =2.0.35 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1592 is considered a medium severity vulnerability due to its potential for exposing sensitive information.
To fix CVE-2002-1592, upgrade to a patched version of Apache HTTP Server that does not expose the full path in error messages.
CVE-2002-1592 affects Apache HTTP Server versions 2.0 through 2.0.35.
CVE-2002-1592 is an information disclosure vulnerability that arises from improper error handling in CGI applications.
Yes, CVE-2002-1592 can be exploited remotely by attackers who can trigger CGI errors and access sensitive path information.