Apache before 1.3.20 on Windows and OS/2 systems allows remote attackers to cause a denial of service (GPF) via an HTTP request for a URI that contains a large number of / (slash) or other characters, which causes certain functions to dereference a null pointer.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Http_server | Apache | 1.3.12 (including) | 1.3.12 (including) |
| Http_server | Apache | 1.3.14 (including) | 1.3.14 (including) |
| Http_server | Apache | 1.3.15 (including) | 1.3.15 (including) |
| Http_server | Apache | 1.3.16 (including) | 1.3.16 (including) |
| Http_server | Apache | 1.3.17 (including) | 1.3.17 (including) |
| Http_server | Apache | 1.3.18 (including) | 1.3.18 (including) |
| Http_server | Apache | 1.3.19 (including) | 1.3.19 (including) |