CVE-2003-0189: Medium severity Apache HTTP Server vulnerability
The authentication module for Apache 2.0.40 through 2.0.45 on Unix does not properly handle threads safely when using the cryptr or crypt functions, which allows remote attackers to cause a denial of service (failed Basic authentication with valid usernames and passwords) when a threaded MPM is used.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0189?
CVE-2003-0189 has a severity level that may lead to denial of service in affected versions of Apache.
How do I fix CVE-2003-0189?
To fix CVE-2003-0189, upgrade to a version of Apache HTTP Server that is not affected, specifically versions after 2.0.45.
Which versions of Apache HTTP Server are affected by CVE-2003-0189?
CVE-2003-0189 affects Apache HTTP Server versions 2.0.40 through 2.0.45.
Can CVE-2003-0189 be exploited remotely?
Yes, CVE-2003-0189 can be exploited remotely, allowing attackers to cause a denial of service.
What are the symptoms of an exploit for CVE-2003-0189?
The symptoms of an exploit for CVE-2003-0189 include failed Basic authentication attempts, even with valid credentials.