CVE-2002-0839

Published Oct 11, 2002

Last updated 10 days ago

Overview

Description
The shared memory scoreboard in the HTTP daemon for Apache 1.3.x before 1.3.27 allows any user running as the Apache UID to send a SIGUSR1 signal to any process as root, resulting in a denial of service (process kill) or possibly other behaviors that would not normally be allowed, by modifying the parent[].pid and parent[].last_rtime segments in the scoreboard.
Source
cve@mitre.org
NVD status
Modified
Products
http_server, debian_linux

Risk scores

CVSS 2.0

Type
Primary
Base score
7.2
Impact score
10
Exploitability score
3.9
Vector string
AV:L/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

nvd@nist.gov
NVD-CWE-noinfo

Social media

Hype score
Not currently trending

Vendor comments

  • ApacheFixed in Apache HTTP Server 1.3.27: http://httpd.apache.org/security/vulnerabilities_13.html

Configurations

References

Sources include official advisories and independent security research.