CVE-2004-0747
SITIC Security Advisory 2004.2
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Buffer overflow in Apache 2.0.50 and earlier allows local users to gain apache privileges via a .htaccess file that causes the overflow during expansion of environment variables.
Desbordamiento de búfer en Apache 2.0.50 y anteriores permite a usuarios locales ganar privilegios mediante un fichero .htaccess que causa un desbordamiento durante la expansión de variables de entorno.
Two new vulnerabilities have been discovered in Apache. Through the testing of Apache by using the Codenomicon HTTP Test Tool, the ASF Security Team has discovered a bug in the apr-util library, which can lead to arbitrary code execution. SITIC have discovered that Apache suffers from a buffer overflow when expanding environment variables in configuration files such as .htaccess and httpd.conf, leading to possible privilege escalation. These vulnerabilities affect versions 2.0.35 through 2.0.50.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2004-07-26 CVE Reserved
- 2004-09-15 CVE Published
- 2025-01-16 CVE Updated
- 2025-07-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-131: Incorrect Calculation of Buffer Size
CAPEC
References (27)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/12540 | Broken Link | |
http://secunia.com/advisories/34920 | Broken Link | |
http://securitytracker.com/id?1011303 | Broken Link | |
http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=205147 | Broken Link | |
http://www.kb.cert.org/vuls/id/481998 | Third Party Advisory |
|
https://exchange.xforce.ibmcloud.com/vulnerabilities/17384 | Third Party Advisory | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11561 | Broken Link |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | >= 2.0.35 < 2.0.51 Search vendor "Apache" for product "Http Server" and version " >= 2.0.35 < 2.0.51" | - |
Affected
|