AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2003-0844

HIGH · CVSS 7.1 EPSS 0.32%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2003-11-17 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2003-0844
Severity
HIGH
CVSS
7.1
EPSS
0.32%
Windows Apache

Original NVD Description

mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode without the Apache log, allows local users to overwrite arbitrary files via (1) a symlink attack on predictable temporary filenames on Unix systems, or (2) an NTFS hard link on Windows systems when the "Strengthen default permissions of internal system objects" policy is not enabled.