« Volver al listado

CVE-2002-2103

Estado: ModificadaMedia (5)—

Apache before 1.3.24, when writing to the log file, records a spoofed hostname from the reverse lookup of an IP address, even when a double-reverse lookup fails, which allows remote attackers to hide the original source of activities.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2002-2103",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2002-12-31T05:00:00.000",
  "references": [
    {
      "url": "http://www.apache.org/dist/httpd/CHANGES_1.3",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.iss.net/security_center/static/8629.php",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/4358",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.apache.org/dist/httpd/CHANGES_1.3",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.iss.net/security_center/static/8629.php",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/4358",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Apache before 1.3.24, when writing to the log file, records a spoofed hostname from the reverse lookup of an IP address, even when a double-reverse lookup fails, which allows remote attackers to hide the original source of activities."
    }
  ],
  "lastModified": "2026-06-16T22:00:39.597",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apache:http_server:1.3.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "19C8989C-D8A6-4AE9-99B6-F2DAE5999EB6"
            },
            {
              "criteria": "cpe:2.3:a:apache:http_server:1.3.11:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7B6EE0E2-D608-4E72-A0E5-F407511405C2"
            },
            {
              "criteria": "cpe:2.3:a:apache:http_server:1.3.12:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "33FD6791-3B84-40CA-BCF4-B5637B172F2A"
            },
            {
              "criteria": "cpe:2.3:a:apache:http_server:1.3.13:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "06F447C8-15FE-44DE-86AD-5E2D496AB2A6"
            },
            {
              "criteria": "cpe:2.3:a:apache:http_server:1.3.14:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6DDD2F69-CFD4-4DEA-B43A-1337EEFA95A3"
            },
            {
              "criteria": "cpe:2.3:a:apache:http_server:1.3.15:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A4955E57-9C5D-40C2-BD5F-A383FF3C33FB"
            },
            {
              "criteria": "cpe:2.3:a:apache:http_server:1.3.16:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6A7607F8-6C2A-4976-A861-3BEE1F45002B"
            },
            {
              "criteria": "cpe:2.3:a:apache:http_server:1.3.17:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0A80B17D-FD66-40BD-9ADC-FE7A3944A696"
            },
            {
              "criteria": "cpe:2.3:a:apache:http_server:1.3.18:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "713ADED4-CBE5-40C3-A128-99CFABF24560"
            },
            {
              "criteria": "cpe:2.3:a:apache:http_server:1.3.19:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "70FA0B8E-1A90-4939-871A-38B9E93BCCC1"
            },
            {
              "criteria": "cpe:2.3:a:apache:http_server:1.3.20:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "83BDEAE5-29B9-48E3-93FA-F30832044C9A"
            },
            {
              "criteria": "cpe:2.3:a:apache:http_server:1.3.22:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A2720E06-1B0E-4BFE-8C85-A17E597BB151"
            },
            {
              "criteria": "cpe:2.3:a:apache:http_server:1.3.23:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3EE1DECF-36C7-4968-8B7A-7A2034C2A957"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "vendorComments": [
    {
      "comment": "Not vulnerable. This issue did not affect the versions of Apache HTTP server as shipped with Red Hat Enterprise Linux 2.1, 3, or 4.",
      "lastModified": "2006-08-30T00:00:00",
      "organization": "Red Hat"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}