7.2

CVE-2002-0839

The shared memory scoreboard in the HTTP daemon for Apache 1.3.x before 1.3.27 allows any user running as the Apache UID to send a SIGUSR1 signal to any process as root, resulting in a denial of service (process kill) or possibly other behaviors that would not normally be allowed, by modifying the parent[].pid and parent[].last_rtime segments in the scoreboard.

Data is provided by the National Vulnerability Database (NVD)
ApacheHTTP Server Version >= 1.3.0 < 1.3.27
DebianDebian Linux Version2.2
DebianDebian Linux Version3.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.14% 0.35
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
http://marc.info/?l=bugtraq&m=103376585508776&w=2
Third Party Advisory
Mailing List
Issue Tracking
http://marc.info/?l=bugtraq&m=130497311408250&w=2
Third Party Advisory
Mailing List
Issue Tracking
http://online.securityfocus.com/advisories/4617
Third Party Advisory
VDB Entry
http://www.apacheweek.com/issues/02-10-04
Vendor Advisory
Release Notes
http://www.securityfocus.com/bid/5884
Third Party Advisory
VDB Entry