Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures.
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9458
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A864
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A863
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3799
https://exchange.xforce.ibmcloud.com/vulnerabilities/13400
http://www.securityfocus.com/bid/9504
http://www.securityfocus.com/bid/8911
http://www.securityfocus.com/archive/1/342674
http://www.securityfocus.com/advisories/6079
http://www.redhat.com/support/errata/RHSA-2005-816.html
http://www.redhat.com/support/errata/RHSA-2004-015.html
http://www.redhat.com/support/errata/RHSA-2003-405.html
http://www.redhat.com/support/errata/RHSA-2003-360.html
http://www.redhat.com/support/errata/RHSA-2003-320.html
http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:103
http://www.kb.cert.org/vuls/id/549142
http://www.kb.cert.org/vuls/id/434566
http://sunsolve.sun.com/search/document.do?assetkey=1-26-101841-1
http://sunsolve.sun.com/search/document.do?assetkey=1-26-101444-1
http://secunia.com/advisories/10593
http://secunia.com/advisories/10580
http://secunia.com/advisories/10463
http://secunia.com/advisories/10264
http://secunia.com/advisories/10260
http://secunia.com/advisories/10153
http://secunia.com/advisories/10114
http://secunia.com/advisories/10112
http://secunia.com/advisories/10102
http://secunia.com/advisories/10098
http://secunia.com/advisories/10096
http://marc.info/?l=bugtraq&m=130497311408250&w=2
http://marc.info/?l=bugtraq&m=106761802305141&w=2
http://lists.apple.com/mhonarc/security-announce/msg00045.html
http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html