CVE-2002-0392
82Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 95%
from disclosure to weapon0 days
Published on NVDApr 2
1st PoCJun 17
metasploitJun 19
VulnCheckJun 17
exploitation probability
95%top 1% of all CVEs
observed exploitation
yesVulnCheck
3 public exploit(s)
Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a chunk-encoded HTTP request that causes Apache to use an incorrect size.
Affected products
n/a · n/apublic PoCs found — 3✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/21559exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/21560exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/16782⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-029.0.txtftp://ftp.caldera.com/pub/updates/OpenServer/CSSA-2002-SCO.32ftp://ftp.caldera.com/pub/updates/OpenUNIX/CSSA-2002-SCO.31ftp://patches.sgi.com/support/free/security/advisories/20020605-01-Aftp://patches.sgi.com/support/free/security/advisories/20020605-01-Ihttp://archives.neohapsis.com/archives/bugtraq/2002-06/0235.htmlhttp://archives.neohapsis.com/archives/bugtraq/2002-06/0266.htmlhttp://distro.conectiva.com/atualizacoes/?id=a&anuncio=000498http://frontal2.mandriva.com/security/advisories?name=MDKSA-2002:039http://httpd.apache.org/info/security_bulletin_20020617.txthttp://online.securityfocus.com/advisories/4240http://online.securityfocus.com/advisories/4257