CVE-2001-1342
Published May 12, 2001
Last updated a year ago
Overview
- Description
- Apache before 1.3.20 on Windows and OS/2 systems allows remote attackers to cause a denial of service (GPF) via an HTTP request for a URI that contains a large number of / (slash) or other characters, which causes certain functions to dereference a null pointer.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:N/I:N/A:P
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Vendor comments
- ApacheFixed in Apache HTTP Server 1.3.20: http://httpd.apache.org/security/vulnerabilities_13.html
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:apache:http_server:1.3.12:*:win32:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F9778DCA-00B3-4C15-B1B7-05738CD61E62" }, { "criteria": "cpe:2.3:a:apache:http_server:1.3.14:*:win32:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "14E06755-5DEB-450C-A718-D1531E9986F4" }, { "criteria": "cpe:2.3:a:apache:http_server:1.3.15:*:win32:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8F572870-41BF-40B5-B202-136449814A2D" }, { "criteria": "cpe:2.3:a:apache:http_server:1.3.16:*:win32:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E593B74E-894C-4286-8F41-69C3435D9F2B" }, { "criteria": "cpe:2.3:a:apache:http_server:1.3.17:*:win32:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "780FEC59-8720-4C81-8924-F25577633B24" }, { "criteria": "cpe:2.3:a:apache:http_server:1.3.18:*:win32:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A6938AFA-D836-4F85-9595-27799D476F0A" }, { "criteria": "cpe:2.3:a:apache:http_server:1.3.19:*:win32:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "46B27279-DB34-4B9C-A84C-3ED872A43599" } ], "operator": "OR" } ] } ]