CVE-2003-0245 describes a denial-of-service vulnerability in the apr_psprintf function within the Apache Portable Runtime (APR) library, affecting Apache HTTP Server versions 2.0.37 through 2.0.45. This flaw allows remote attackers to crash the server and potentially execute arbitrary code by supplying excessively long strings, as demonstrated with XML objects to mod_dav. With a CVSS score of 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P) and a FAUCET Risk Score of 99/100, it indicates a high-risk, easily exploitable issue with potential for significant impact. While not listed on CISA's KEV catalog, exploit code exists on ExploitDB, and its EPSS score suggests a high likelihood of exploitation, despite minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0.37CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.0.37:*:*:*:*:*:*:* | ||
2.0.38CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.0.38:*:*:*:*:*:*:* | ||
2.0.39CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.0.39:*:*:*:*:*:*:* | ||
2.0.40CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.0.40:*:*:*:*:*:*:* | ||
2.0.41CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.0.41:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.