Vulnerability record · CVE-2003-0245 · published 9 June 2003
CVE-2003-0245: Apache HTTP Server APR apr_psprintf long string flaw
Apache · Http Server
The apr_psprintf function in the Apache Portable Runtime library, used by Apache HTTP Server 2.0.37 through 2.0.45, mishandles long strings and can crash the server, with a possibility of arbitrary code execution. The flaw is remotely reachable, for example through XML objects sent to mod_dav, so an unauthenticated attacker can disrupt or potentially compromise the service.
Description
Vulnerability in the apr_psprintf function in the Apache Portable Runtime (APR) library for Apache 2.0.37 through 2.0.45 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long strings, as demonstrated using XML objects to mod_dav, and possibly other vectors.
AV:N/AC:L/Au:N/C:N/I:N/A:P
Automated analysis
high priorityThe flaw is remotely reachable without authentication, can cause denial of service and possibly code execution, and has a high EPSS score despite not being in KEV.
What it is
The apr_psprintf function in the Apache Portable Runtime library, used by Apache HTTP Server 2.0.37 through 2.0.45, mishandles long strings and can crash the server, with a possibility of arbitrary code execution. The flaw is remotely reachable, for example through XML objects sent to mod_dav, so an unauthenticated attacker can disrupt or potentially compromise the service.
Impact
An attacker can cause a denial of service by crashing the Apache process and may be able to execute arbitrary code in the server context. Successful code execution would give the attacker the privileges of the web server process.
Attack surface
Reachable over the network with no authentication required, as reflected by the AV:N/AC:L/Au:N vector. The description names mod_dav XML objects as a demonstrated vector, and other paths into apr_psprintf are possible; no user interaction is indicated.
Exploitation
CISA KEV does not list this CVE, but EPSS is high at 0.63456 (99.17th percentile), indicating a meaningful predicted likelihood of exploitation activity. Reference tags show vendor patches and advisories but no public exploit tag.
What to do
- Upgrade Apache HTTP Server to a version after 2.0.45 that contains the APR fix, or apply the vendor patch referenced in the Apache announcement.
- If immediate upgrade is not possible, disable or restrict mod_dav and other modules that pass untrusted long strings into apr_psprintf.
- Apply the Red Hat or Mandriva distribution errata if running the vendor-packaged Apache build.
- Limit network exposure of the web server and place it behind a reverse proxy or WAF that can reject oversized or malformed request bodies.
- Monitor for and restart crashed Apache worker processes while remediation is pending.
Detection
- Monitor Apache error and system logs for repeated child process crashes, segfaults or abnormal worker restarts.
- Inspect HTTP request logs for unusually long request bodies or XML payloads directed at DAV-enabled paths.
- Alert on core dumps or crash reports originating from the httpd process.
- Track EPSS and vendor advisories for this CVE to prioritize patching of any remaining 2.0.37-2.0.45 instances.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2003-0245 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2003-0245), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.