CVE-2003-0993

Description

mod_access in Apache 1.3 before 1.3.30, when running big-endian 64-bit platforms, does not properly parse Allow/Deny rules using IP addresses without a netmask, which could allow remote attackers to bypass intended access restrictions.

Risk Information

Base Score
9.1
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
EPSS Score
Exploitation Probability
5.029

Associated Vulnerability

VulnerabilityOS Platform
Update Apache to version 1.3.29Windows
Vulnerabilities CVE-2003-0020,CVE-2003-0987,CVE-2003-0993 are fixed in Apache 1.3.31Windows
Update Apache to version 1.3.29 (For Linux)Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234