Back

MEDIUM

security flaw

Published May 30, 2003

Description

The authentication module for Apache 2.0.40 through 2.0.45 on Unix does not properly handle threads safely when using the crypt_r or crypt functions, which allows remote attackers to cause a denial of service (failed Basic authentication with valid usernames and passwords) when a threaded MPM is used.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (0)

No CWE recorded.

References (26)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 30, 2003
Updated Aug 8, 2024
Reserved Apr 1, 2003
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date May 28, 2003