20030601 Mod_gzip Debug Mode Vulnerabilitiesmailing list
http://marc.info/?l=bugtraq&m=105457180009860&w=2 CVE-2003-0842
Apache mod_gzip (with debug_mode) 1.2.26.1a - Remote Overflow
Record summary
CVE-2003-0842 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Stack-based buffer overflow in mod_gzip_printf for mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode, allows remote attackers to execute arbitrary code via a long filename in a GET request with an "Accept-Encoding: gzip" header.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBApache mod_gzip (with debug_mode) 1.2.26.1a - Remote OverflowExploitDB exploitby xCrZxNot analyzed1 file
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2003-0842