Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2, when RewriteEngine is enabled, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted URLs that are not properly handled using certain rewrite rules.
2006-07-28T18:02:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 7.6 (HIGH)
AV:N/AC:H/Au:N/C:C/I:C/A:C
4.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | apache | http_server | < 1.3.37 | Yes |
Application | apache | http_server | < 2.0.59 | Yes |
Application | apache | http_server | < 2.2.3 | Yes |
Operating System | canonical | ubuntu_linux | 5.04 | Yes |
Operating System | canonical | ubuntu_linux | 5.10 | Yes |
Operating System | canonical | ubuntu_linux | 6.06 | Yes |
Operating System | debian | debian_linux | 3.1 | Yes |