CVE-2002-1850 describes a denial-of-service vulnerability in Apache HTTP Server versions 2.0.39 and 2.0.40, specifically within its mod_cgi module. This flaw allows local users, and potentially remote attackers, to trigger a read/write deadlock by causing a CGI script to output an excessive amount of data to stderr, leading to a server hang and memory exhaustion. With a CVSS score of 7.5 (High), this vulnerability is easily exploitable over the network with low attack complexity, resulting in a complete loss of availability. While not listed in CISA's KEV catalog or having Metasploit/Nuclei modules, an ExploitDB entry (EDB-21854) confirms the existence of exploit code, and the vulnerability has garnered significant community discussion, indicating awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0.39CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.0.39:*:*:*:*:*:*:* | ||
2.0.40CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.0.40:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.