CVE-2004-0747

Publication date 20 October 2004

Last updated 17 July 2025


Ubuntu priority

Cvss 3 Severity Score

7.8 · High

Score breakdown

Description

Buffer overflow in Apache 2.0.50 and earlier allows local users to gain apache privileges via a .htaccess file that causes the overflow during expansion of environment variables.

Status

Package Ubuntu Release Status
apache2 7.04 feisty
Fixed 2.2.3-3.2ubuntu0.1
6.10 edgy
Fixed 2.0.55-4ubuntu4.1
6.06 LTS dapper
Fixed 2.0.55-4ubuntu2.2

Severity score breakdown

Parameter Value
Base score 7.8 · High
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Scope Unchanged
Confidentiality High
Integrity impact High
Availability impact High
Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H