CVE-2004-0940

Publication date 9 February 2005

Last updated 17 July 2025


Ubuntu priority

Cvss 3 Severity Score

7.8 · High

Score breakdown

Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrary code as the apache user via SSI (XSSI) documents that trigger a length calculation error.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
apache 7.04 feisty
Fixed 1.3.34-4ubuntu1
6.10 edgy
Fixed 1.3.34-4ubuntu1
6.06 LTS dapper
Fixed 1.3.34-2ubuntu0.1

Severity score breakdown

Parameter Value
Base score 7.8 · High
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Scope Unchanged
Confidentiality High
Integrity impact High
Availability impact High
Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H