Tenable Network Security
Solutions Products Nessus Demos Partners Online Store
Nessus
Download
Plugins
     Newest Plugins
     Obtain an activation code
     View all plugins
     Search
Documentation
Register
Buy Now
ProfessionalFeed Support
Bugs
All the Tenable Products

Apache < 1.3.29 Multiple Modules Local Overflow

This script is Copyright (C) 2003-2010 Tenable Network Security, Inc.

FamilyWeb Servers
Nessus Plugin ID11915 (apache_1_3_29.nasl)
Bugtraq ID8911
CVE IDCVE-2003-0542

Description:
Synopsis :

The remote web server is affected by multiple local buffer overflow
vulnerabilities.

Description :

The remote host appears to be running a version of the Apache web
server which is older than 1.3.29. Such versions are reportedly
affected by local buffer overflow vulnerabilities in the mod_alias and
mod_rewrite modules. An attacker could exploit these vulnerabilities
to execute arbitrary code in the context of the affected application.

*** Note that Nessus solely relied on the version number
*** of the remote server to issue this warning. This might
*** be a false positive

See also :

http://www.securityfocus.com/archive/1/342674/30/0/threaded

Solution :

Upgrade to Apache web server version 1.3.29 or later.

Risk factor :

High / CVSS Base Score : 7.2
(CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
About us | Whitepapers | Training | Discussion Forums | Support Portal | Blog | RSS feeds | Contact us | Legal | Privacy

© Copyright 2002 - 2010 Tenable Network Security(R). All Rights Reserved.

This is the web site for the Nessus Vulnerability Scanner from Tenable Network Security. If you are looking for the probabilistic analysis software from Southwest Research Institute, please visit www.nessus.swri.org