CVE-2003-1198: Medium severity Cherokee Cherokee HTTPD vulnerability
Published Dec 26, 2003
·Updated
connection.c in Cherokee web server before 0.4.6 allows remote attackers to cause a denial of service via an HTTP POST request without a Content-Length header field.
Affected Software
8 affected components
Cherokee Cherokee HTTPD=0.4.6
Cherokee Cherokee HTTPD=0.2
Cherokee Cherokee HTTPD=0.1.6
Cherokee Cherokee HTTPD=0.2.6
Cherokee Cherokee HTTPD=0.2.5
Cherokee Cherokee HTTPD=0.1
Cherokee Cherokee HTTPD=0.2.7
Cherokee Cherokee HTTPD=0.1.5
Remediation
Patch Available
Patch Available
Event History
Dec 26, 2003
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityAffected Software
May 10, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2003-1198?
CVE-2003-1198 is classified as a denial of service vulnerability.
2
How do I fix CVE-2003-1198?
To fix CVE-2003-1198, upgrade the Cherokee web server to version 0.4.6 or later.
3
What versions of Cherokee web server are affected by CVE-2003-1198?
CVE-2003-1198 affects Cherokee web server versions from 0.1 up to and including 0.4.5.
4
What type of attack does CVE-2003-1198 allow?
CVE-2003-1198 allows remote attackers to cause a denial of service through an HTTP POST request without a Content-Length header.
5
Can CVE-2003-1198 be exploited remotely?
Yes, CVE-2003-1198 can be exploited remotely, affecting the availability of affected servers.