CVE-2003-0789: Critical severity Apache HTTP Server vulnerability
Published Oct 30, 2003
·Updated
modcgid in Apache before 2.0.48, when using a threaded MPM, does not properly handle CGI redirect paths, which could cause Apache to send the output of a CGI program to the wrong client.
Affected Software
1 affected component
Apache HTTP Server>=2.0.35<2.0.48
Event History
Oct 30, 2003
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Nov 3, 2003
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2003-0789?
CVE-2003-0789 is classified as a medium severity vulnerability.
2
How do I fix CVE-2003-0789?
To fix CVE-2003-0789, upgrade Apache HTTP Server to version 2.0.48 or later.
3
What systems are affected by CVE-2003-0789?
CVE-2003-0789 affects Apache versions below 2.0.48 when using a threaded MPM.
4
What type of vulnerability is CVE-2003-0789?
CVE-2003-0789 is a security vulnerability related to improper handling of CGI redirect paths in Apache.
5
Can CVE-2003-0789 lead to information disclosure?
Yes, CVE-2003-0789 can lead to information disclosure by sending output intended for one client to another.