Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2002-0839

The shared memory scoreboard in the HTTP daemon for Apache 1.3.x before 1.3.27 allows any user running as the Apache UID to send a SIGUSR1 signal to any process as root, resulting in a denial of service (process kill) or possibly other behaviors that would not normally be allowed, by modifying the parent[].pid and parent[].last_rtime segments in the scoreboard.

  • Published: Oct 11, 2002
  • Updated: Apr 13, 2023
  • CVE: CVE-2002-0839
  • Severity: High
  • Exploit:

CVSS v2:

  • Severity: High
  • Score: 7.2
  • AV:L/AC:L/Au:N/C:C/I:C/A:C

No CWE or OWASP classifications available.

Software From Fixed in
apache / http_server 1.3.0 1.3.27
debian / debian_linux 2.2 2.2.x
debian / debian_linux 3.0 3.0.x