Vulnerability Description
Heap-based buffer overflow in the sec_filter_out function in mod_security 1.7RC1 through 1.7.1 in Apache 2 allows remote attackers to execute arbitrary code via a server side script that sends a large amount of data.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mod Security | Mod Security | 1.7 |
References
- http://adsystems.com.pl/adg-mod_security171.txt
- http://secunia.com/advisories/10085PatchVendor Advisory
- http://securitytracker.com/id?1008025ExploitPatch
- http://www.modsecurity.org/download/CHANGES
- http://www.securityfocus.com/archive/1/342767Patch
- http://www.securityfocus.com/bid/8919Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/13543
- http://adsystems.com.pl/adg-mod_security171.txt
- http://secunia.com/advisories/10085PatchVendor Advisory
- http://securitytracker.com/id?1008025ExploitPatch
- http://www.modsecurity.org/download/CHANGES
- http://www.securityfocus.com/archive/1/342767Patch
- http://www.securityfocus.com/bid/8919Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/13543
FAQ
What is CVE-2003-1171?
CVE-2003-1171 is a vulnerability with a CVSS score of 7.5 (HIGH). Heap-based buffer overflow in the sec_filter_out function in mod_security 1.7RC1 through 1.7.1 in Apache 2 allows remote attackers to execute arbitrary code via a server side script that sends a large...
How severe is CVE-2003-1171?
CVE-2003-1171 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2003-1171?
Check the references section above for vendor advisories and patch information. Affected products include: Mod Security Mod Security.