Description
The mod_php module for the Apache HTTP Server allows local users with write access to PHP scripts to send signals to the server's process group and use the server's file descriptors, as demonstrated by sending a STOP signal, then intercepting incoming connections on the server's TCP port. NOTE: the PHP developer has disputed this vulnerability, saying "The opened file descriptors are opened by Apache. It is the job of Apache to protect them ... Not a bug in PHP.
Published: 2006-10-23
Score: 4.3 Medium
EPSS: 1.2% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.01279}

epss

{'score': 0.00516}


Subscriptions

Apache Http Server
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-08T02:19:46.131Z

Reserved: 2006-10-23T00:00:00.000Z

Link: CVE-2003-1307

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2003-12-31T05:00:00.000

Modified: 2026-04-16T00:27:16.627

Link: CVE-2003-1307

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses