First published: Fri Mar 28 2003(Updated: )
Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter terminal escape sequences from its access logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences, a different vulnerability than CVE-2003-0020.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache HTTP Server | >=1.3.0<1.3.26 | |
Apache HTTP Server | >=2.0.0<2.0.46 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0083 is considered a moderate severity vulnerability due to potential exploitation through terminal escape sequences.
To fix CVE-2003-0083, upgrade to Apache version 1.3.25 or later, or version 2.0.46 or later.
The risks associated with CVE-2003-0083 include the potential for attackers to exploit terminal emulator vulnerabilities by injecting escape sequences.
While CVE-2003-0083 is an older vulnerability, it remains relevant for systems that have not been updated and continue to run affected versions of Apache.
CVE-2003-0083 affects Apache 1.3 versions prior to 1.3.25 and Apache 2.0 versions prior to 2.0.46.