CVE-2002-0842
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Format string vulnerability in certain third party modifications to mod_dav for logging bad gateway messages (e.g. Oracle9i Application Server 9.0.2) allows remote attackers to execute arbitrary code via a destination URI that forces a "502 Bad Gateway" response, which causes the format string specifiers to be returned from dav_lookup_uri() in mod_dav.c, which is then used in a call to ap_log_rerror().
Vulnerabilidad de cadena de formato en ciertas modificaciones de terceros a mod_dav para el registro de mesajes de pasarela erroneos (por ejemplo Oracle 9i Application Server 9.0.2) permite a atacantes remotos ejecutar código arbitrario mediante una URI de destino que fuerza una respuesta "502 Bad Gateway", lo que causa que los especificadores de cadena de formato sean devueltos de dav_lookup_uri() en mod_dav.c, que es entonces usado para llamar a ap_log_error().
CVSS Scores
SSVC
- Decision:-
Timeline
- 2002-08-08 CVE Reserved
- 2003-03-03 CVE Published
- 2024-08-08 CVE Updated
- 2024-08-08 First Exploit
- 2024-09-16 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (11)
URL | Tag | Source |
---|---|---|
http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0076.html | Mailing List | |
http://marc.info/?l=bugtraq&m=104549708626309&w=2 | Mailing List | |
http://marc.info/?l=bugtraq&m=104559446010858&w=2 | Mailing List | |
http://marc.info/?l=bugtraq&m=104560577227981&w=2 | Mailing List | |
http://www.cert.org/advisories/CA-2003-05.html | Third Party Advisory | |
http://www.ciac.org/ciac/bulletins/n-046.shtml | Government Resource | |
http://www.nextgenss.com/advisories/ora-appservfmtst.txt | X_refsource_misc | |
http://www.securityfocus.com/bid/6846 | Vdb Entry |
URL | Date | SRC |
---|---|---|
http://www.kb.cert.org/vuls/id/849993 | 2024-08-08 |
URL | Date | SRC |
---|---|---|
http://otn.oracle.com/deploy/security/pdf/2003alert52.pdf | 2016-10-18 |
URL | Date | SRC |
---|---|---|
http://www.iss.net/security_center/static/11330.php | 2016-10-18 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Oracle Search vendor "Oracle" | Application Server Search vendor "Oracle" for product "Application Server" | 9.0.2 Search vendor "Oracle" for product "Application Server" and version "9.0.2" | - |
Affected
|