CVE-2003-0016: High severity Apache HTTP Server vulnerability
Apache before 2.0.44, when running on unpatched Windows 9x and Me operating systems, allows remote attackers to cause a denial of service or execute arbitrary code via an HTTP request containing MS-DOS device names.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Http Serverto a version that resolves this vulnerability.Fixed in 2.0.44 - Compensating control
Do not run Apache Http Server on unpatched Windows 9x or Windows Me systems. Isolate any such hosts from untrusted networks (for example, with firewall rules or network segmentation) until the systems can be upgraded or replaced.
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0016?
CVE-2003-0016 has the potential for high severity as it can cause denial of service and allows execution of arbitrary code.
How do I fix CVE-2003-0016?
To fix CVE-2003-0016, update Apache HTTP Server to version 2.0.44 or later.
Which versions of Apache are affected by CVE-2003-0016?
Apache HTTP Server versions 2.0.36 through 2.0.43 are affected by CVE-2003-0016.
What operating systems are susceptible to CVE-2003-0016?
CVE-2003-0016 specifically affects Apache running on unpatched Windows 9x and Me operating systems.
What type of attack does CVE-2003-0016 enable?
CVE-2003-0016 enables remote attackers to craft HTTP requests that can result in a denial of service or arbitrary code execution.