CVE-2003-0993: High severity Apache HTTP Server vulnerability
modaccess in Apache 1.3 before 1.3.30, when running big-endian 64-bit platforms, does not properly parse Allow/Deny rules using IP addresses without a netmask, which could allow remote attackers to bypass intended access restrictions.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0993?
CVE-2003-0993 is classified as a moderate vulnerability that could allow remote attackers to bypass access restrictions.
How do I fix CVE-2003-0993?
To fix CVE-2003-0993, upgrade to Apache HTTP Server version 1.3.30 or later.
What are the affected versions for CVE-2003-0993?
CVE-2003-0993 affects Apache HTTP Server versions 1.3 up to 1.3.29 on big-endian 64-bit platforms.
Can CVE-2003-0993 be exploited remotely?
Yes, CVE-2003-0993 can be exploited by remote attackers to bypass intended access restrictions.
What are the implications of CVE-2003-0993 for my Apache server?
Due to CVE-2003-0993, your Apache server may unintentionally allow some unauthorized access if it uses Allow/Deny rules without a netmask.