High severity7.5NVD Advisory· Published Dec 31, 2002· Updated Apr 16, 2026
CVE-2002-1850
CVE-2002-1850
Description
mod_cgi in Apache 2.0.39 and 2.0.40 allows local users and possibly remote attackers to cause a denial of service (hang and memory consumption) by causing a CGI script to send a large amount of data to stderr, which results in a read/write deadlock between httpd and the CGI script.
Affected products
2cpe:2.3:a:apache:http_server:2.0.39:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:apache:http_server:2.0.39:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.0.40:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- issues.apache.org/bugzilla/show_bug.cginvdIssue TrackingPatch
- securitytracker.com/idnvdBroken LinkPatchThird Party AdvisoryVDB Entry
- www.iss.net/security_center/static/10200.phpnvdBroken LinkPatch
- www.securityfocus.com/bid/8725nvdBroken LinkPatchThird Party AdvisoryVDB Entry
- seclists.org/bugtraq/2002/Sep/0253.htmlnvdExploitMailing ListThird Party Advisory
- www.securityfocus.com/bid/5787nvdBroken LinkExploitThird Party AdvisoryVDB Entry
- cvs.apache.org/viewcvs.cgi/httpd-2.0/modules/generators/mod_cgi.cnvdBroken Link
- issues.apache.org/bugzilla/show_bug.cginvdIssue Tracking
- marc.infonvdMailing List
News mentions
0No linked articles in our index yet.