First published: Thu Oct 30 2003(Updated: )
mod_cgid in Apache before 2.0.48, when using a threaded MPM, does not properly handle CGI redirect paths, which could cause Apache to send the output of a CGI program to the wrong client.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Http Server | >=2.0.35<2.0.48 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0789 is classified as a medium severity vulnerability.
To fix CVE-2003-0789, upgrade Apache HTTP Server to version 2.0.48 or later.
CVE-2003-0789 affects Apache versions below 2.0.48 when using a threaded MPM.
CVE-2003-0789 is a security vulnerability related to improper handling of CGI redirect paths in Apache.
Yes, CVE-2003-0789 can lead to information disclosure by sending output intended for one client to another.