Apache MS-DOS Device Name Vulnerability

  Severity: HIGH
  CVE Identifier: CVE-2003-0016
  Advisory Date: JUL 21, 2015

  DESCRIPTION

Apache before 2.0.44, when running on unpatched Windows 9x and Me operating systems, allows remote attackers to cause a denial of service or execute arbitrary code via an HTTP request containing MS-DOS device names.

  TREND MICRO PROTECTION INFORMATION

Apply associated Trend Micro DPI Rules.

  SOLUTION

  Trend Micro Deep Security DPI Rule Number: 1000632
  Trend Micro Deep Security DPI Rule Name: 1000632 - Apache MS-DOS Device Name Vulnerability

  AFFECTED SOFTWARE AND VERSION

  • Apache Software Foundation Apache 2.0.36
  • Apache Software Foundation Apache 2.0.37
  • Apache Software Foundation Apache 2.0.38
  • Apache Software Foundation Apache 2.0.39
  • Apache Software Foundation Apache 2.0.40
  • Apache Software Foundation Apache 2.0.41
  • Apache Software Foundation Apache 2.0.42
  • Apache Software Foundation Apache 2.0.43

Featured Stories