Generation of Error Message Containing Sensitive Information Affecting apache/httpd package, versions [2.0.35,2.0.40)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
58.68% (99th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-APACHEHTTPD-3007288
  • published12 Jan 2022
  • disclosed5 Sept 2002
  • creditUnknown

Introduced: 5 Sep 2002

CVE-2002-0654  (opens in a new tab)
CWE-209  (opens in a new tab)

How to fix?

Upgrade apache/httpd to version 2.0.40 or higher.

Overview

Affected versions of this package are vulnerable to Generation of Error Message Containing Sensitive Information. Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to determine the full pathname of the server via (1) a request for a .var file, which leaks the pathname in the resulting error message, or (2) via an error message that occurs when a script (child process) cannot be invoked.

References

CVSS Base Scores

version 3.1