Back

HIGH

security flaw

Published Oct 5, 2002

Description

The shared memory scoreboard in the HTTP daemon for Apache 1.3.x before 1.3.27 allows any user running as the Apache UID to send a SIGUSR1 signal to any process as root, resulting in a denial of service (process kill) or possibly other behaviors that would not normally be allowed, by modifying the parent[].pid and parent[].last_rtime segments in the scoreboard.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (0)

No CWE recorded.

References (27)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 5, 2002
Updated Aug 8, 2024
Reserved Aug 8, 2002
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Oct 3, 2002