5

CVE-2002-2103

Apache before 1.3.24, when writing to the log file, records a spoofed hostname from the reverse lookup of an IP address, even when a double-reverse lookup fails, which allows remote attackers to hide the original source of activities.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ HTTP Server Version 1.3.9
Apache ≫ HTTP Server Version 1.3.11
Apache ≫ HTTP Server Version 1.3.12
Apache ≫ HTTP Server Version 1.3.13
Apache ≫ HTTP Server Version 1.3.14
Apache ≫ HTTP Server Version 1.3.15
Apache ≫ HTTP Server Version 1.3.16
Apache ≫ HTTP Server Version 1.3.17
Apache ≫ HTTP Server Version 1.3.18
Apache ≫ HTTP Server Version 1.3.19
Apache ≫ HTTP Server Version 1.3.20
Apache ≫ HTTP Server Version 1.3.22
Apache ≫ HTTP Server Version 1.3.23
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 6.06% 0.924
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.apache.org/dist/httpd/CHANGES_1.3
http://www.iss.net/security_center/static/8629.php
Patch
http://www.securityfocus.com/bid/4358
Patch