CVE-2003-1054

mod_access_referer 1.0.2 allows remote attackers to cause a denial of service (crash) via a malformed Referer header that is missing a hostname, as parsed by the ap_parse_uri_components function in Apache, which triggers a null dereference.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mod_access_referer:mod_access_referer:1.0.2:*:*:*:*:*:*:*

History

20 Nov 2024, 23:46

Type Values Removed Values Added
References () http://lists.grok.org.uk/pipermail/full-disclosure/2003-April/004555.html - Patch, Vendor Advisory () http://lists.grok.org.uk/pipermail/full-disclosure/2003-April/004555.html - Patch, Vendor Advisory
References () http://secunia.com/advisories/8612 - Vendor Advisory () http://secunia.com/advisories/8612 - Vendor Advisory
References () http://sourceforge.net/project/shownotes.php?release_id=151905 - Patch () http://sourceforge.net/project/shownotes.php?release_id=151905 - Patch
References () http://www.securityfocus.com/bid/7375 - Exploit, Patch, Vendor Advisory () http://www.securityfocus.com/bid/7375 - Exploit, Patch, Vendor Advisory
References () http://www.vuxml.org/freebsd/af747389-42ba-11d9-bd37-00065be4b5b6.html - Vendor Advisory () http://www.vuxml.org/freebsd/af747389-42ba-11d9-bd37-00065be4b5b6.html - Vendor Advisory

Information

Published : 2003-04-16 04:00

Updated : 2025-04-03 01:03


NVD link : CVE-2003-1054

Mitre link : CVE-2003-1054

CVE.ORG link : CVE-2003-1054


JSON object : View

Products Affected

mod_access_referer

  • mod_access_referer