Korean
<< Back
VID 22502
Severity 30
Port 80, ...
Protocol TCP
Class WWW
Detailed Description The remote host appears to be running a version of Apache 2.x which is older than 2.0.47. Such versions are reportedly affected by multiple vulnerabilities :

- An issue in may occur when the SSLCipherSuite directive is used to upgrade a cipher suite which could lead to a weaker cipher suite being used instead of the upgraded one. (CVE-2003-0192)

- A denial of service vulnerability may exist in the FTP proxy component relating to the use of IPV6 addresses. (CVE-2003-0253)

- An attacker may be able to craft a type-map file that could cause the server to enter an infinite loop. (CVE-2003-0254)

* Note: This check solely relied on the version number of the remote Web server to assess this vulnerability, so this might be a false positive.

* References:
http://www.apache.org/dist/httpd/CHANGES_2.0

* Platforms Affected:
Apache HTTP versions 2.x prior to 2.0.47
Any operating system Any version
Recommendation Upgrade to the latest version of Apache HTTP Server (2.0.47 or later), available from the Apache Software Foundation download site, http://httpd.apache.org/download.cgi

-- OR --

As a workaround, ensure that the affected modules are not in use.
Related URL CVE-2003-0192,CVE-2003-0253,CVE-2003-0254 (CVE)
Related URL 8134,8135,8137,8138 (SecurityFocus)
Related URL (ISS)