Apache 2.0.x < 2.0.45 Multiple Vulnerabilities (DoS, File Write)

medium Nessus Plugin ID 11507

Language:

Synopsis

The remote web server is affected by multiple vulnerabilities.

Description

The remote host is running a version of Apache 2.0.x that is prior to 2.0.45. It is, therefore, reportedly affected by multiple vulnerabilities :

- There is a denial of service attack that could allow an attacker to disable this server remotely.

- The httpd process leaks file descriptors to child processes, such as CGI scripts. An attacker who has the ability to execute arbitrary CGI scripts on this server (including PHP code) would be able to write arbitrary data in the file pointed to (in particular, the log files).

Solution

Upgrade to Apache web server version 2.0.45 or later.

See Also

https://archive.apache.org/dist/httpd/CHANGES_2.0

Plugin Details

Severity: Medium

ID: 11507

File Name: apache_2_0_45.nasl

Version: 1.39

Type: remote

Family: Web Servers

Published: 4/3/2003

Updated: 4/11/2022

Configuration: Enable paranoid mode, Enable thorough checks

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 2.2

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:apache:http_server

Required KB Items: installed_sw/Apache, Settings/ParanoidReport

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 4/2/2003

Reference Information

CVE: CVE-2003-0132

BID: 7254, 7255