CVE-2006-3747

Description

Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2, when RewriteEngine is enabled, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted URLs that are not properly handled using certain rewrite rules.

Risk Information

Base Score
9.8
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
92.739

Associated Vulnerability

VulnerabilityOS Platform
Update Apache to version 2.2.2Windows
Update Apache to version 2.0.59Windows
Update Apache to version 1.3.35Windows
Vulnerabilities CVE-2006-3747 are fixed in Apache 1.3.37Windows
Update Apache to version 2.2.2 (For Linux)Linux
Update Apache to version 2.0.59 (For Linux)Linux
Update Apache to version 1.3.35 (For Linux)Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234