CVE-2002-1850: High severity Apache HTTP Server vulnerability
Published Dec 31, 2002
·Updated
modcgi in Apache 2.0.39 and 2.0.40 allows local users and possibly remote attackers to cause a denial of service (hang and memory consumption) by causing a CGI script to send a large amount of data to stderr, which results in a read/write deadlock between httpd and the CGI script.
Affected Software
2 affected components
Apache HTTP Server=2.0.39
Apache HTTP Server=2.0.40
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Dec 31, 2002
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityWeaknessAffected Software
Jun 28, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1850?
CVE-2002-1850 is classified as a denial of service vulnerability.
2
How do I fix CVE-2002-1850?
To fix CVE-2002-1850, you should upgrade to Apache HTTP Server version 2.0.41 or later.
3
Who is affected by CVE-2002-1850?
CVE-2002-1850 affects users of Apache HTTP Server versions 2.0.39 and 2.0.40.
4
What type of attack does CVE-2002-1850 enable?
CVE-2002-1850 enables attackers to cause a denial of service through resource exhaustion.
5
Can CVE-2002-1850 be exploited remotely?
Yes, CVE-2002-1850 can potentially be exploited by remote attackers.