CVE-2007-3847
The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a denial of service (caching forward proxy process crash) via crafted date headers that trigger a buffer…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 12.9%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a denial of service (caching forward proxy process crash) via crafted date headers that trigger a buffer over-read.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 12.90% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-125
- Affected
- apache/http server · fedoraproject/fedora · fedoraproject/fedora core · canonical/ubuntu linux
- Source
- secalert@redhat.com
References
- http://bugs.gentoo.org/show_bug.cgi?id=186219Issue Tracking, Third Party Advisory
- http://docs.info.apple.com/article.html?artnum=307562Broken Link
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01182588Broken Link
- http://httpd.apache.org/security/vulnerabilities_20.htmlVendor Advisory
- http://httpd.apache.org/security/vulnerabilities_22.htmlVendor Advisory
- http://lists.apple.com/archives/security-announce/2008//May/msg00001.htmlMailing List
- http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.htmlMailing List
- http://lists.vmware.com/pipermail/security-announce/2009/000062.htmlMailing List, Third Party Advisory
- http://marc.info/?l=apache-cvs&m=118592992309395&w=2Issue Tracking, Mailing List, Third Party Advisory
- http://marc.info/?l=apache-httpd-dev&m=118595556504202&w=2Issue Tracking, Mailing List, Third Party Advisory
- http://marc.info/?l=apache-httpd-dev&m=118595953217856&w=2Issue Tracking, Mailing List, Third Party Advisory
- http://secunia.com/advisories/26636Not Applicable
- http://secunia.com/advisories/26722Not Applicable
- http://secunia.com/advisories/26790Not Applicable
- http://secunia.com/advisories/26842Not Applicable
- http://secunia.com/advisories/26952Not Applicable
- http://secunia.com/advisories/26993Not Applicable
- http://secunia.com/advisories/27209Not Applicable
- http://secunia.com/advisories/27563Not Applicable
- http://secunia.com/advisories/27593Not Applicable
- http://secunia.com/advisories/27732Not Applicable
- http://secunia.com/advisories/27882Not Applicable
- http://secunia.com/advisories/27971Not Applicable
- http://secunia.com/advisories/28467Not Applicable
- http://secunia.com/advisories/28606Not Applicable
- http://secunia.com/advisories/28749Not Applicable
- http://secunia.com/advisories/28922Not Applicable
- http://secunia.com/advisories/29420Not Applicable
- http://secunia.com/advisories/30430Not Applicable
- http://security.gentoo.org/glsa/glsa-200711-06.xmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.