High severity7.8NVD Advisory· Published Jul 11, 2002· Updated Apr 16, 2026
CVE-2002-0653
CVE-2002-0653
Description
Off-by-one buffer overflow in the ssl_compat_directive function, as called by the rewrite_command hook for mod_ssl Apache module 2.8.9 and earlier, allows local users to execute arbitrary code as the Apache server user via .htaccess files with long entries.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
18- marc.infonvdMailing ListPatch
- www.securityfocus.com/bid/5084nvdBroken LinkThird Party AdvisoryVDB Entry
- ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-031.0.txtnvdBroken Link
- archives.neohapsis.com/archives/bugtraq/2002-06/0350.htmlnvdBroken Link
- archives.neohapsis.com/archives/hp/2002-q3/0018.htmlnvdBroken Link
- distro.conectiva.com.br/atualizacoes/nvdBroken Link
- marc.infonvdMailing List
- marc.infonvdMailing List
- rhn.redhat.com/errata/RHSA-2002-164.htmlnvdBroken Link
- www.debian.org/security/2002/dsa-135nvdBroken Link
- www.iss.net/security_center/static/9415.phpnvdBroken Link
- www.linux-mandrake.com/en/security/2002/MDKSA-2002-048.phpnvdBroken Link
- www.novell.com/linux/security/advisories/2002_028_mod_ssl.htmlnvdBroken Link
- www.redhat.com/support/errata/RHSA-2002-134.htmlnvdBroken Link
- www.redhat.com/support/errata/RHSA-2002-135.htmlnvdBroken Link
- www.redhat.com/support/errata/RHSA-2002-136.htmlnvdBroken Link
- www.redhat.com/support/errata/RHSA-2002-146.htmlnvdBroken Link
- www.redhat.com/support/errata/RHSA-2003-106.htmlnvdBroken Link
News mentions
0No linked articles in our index yet.