Apache mod_proxy Bug Lets Remote Users Deny Service
|
|
SecurityTracker Alert ID: 1018633
|
|
SecurityTracker URL: http://securitytracker.com/id?1018633
|
|
CVE Reference: CVE-2007-3847
(Links to External Site)
|
Date: Aug 30 2007
|
Impact: Denial of service via network
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Version(s): 2.0.35 - 2.0.59, 2.2.0 - 2.2.4
|
Description: A vulnerability was reported in Apache mod_proxy. A remote user can cause denial of service conditions.
A remote user can send a specially crafted request via the target server (when configured as a reverse proxy) to cause the target
child process to crash.
A remote user can create specially crafted HTML that, when loaded by target user via the target server
(when configured as a forward proxy) to case the target child process to crash.
This may cause denial of service conditions on
systems using a threaded Multi-Processing Module.
|
Impact: A remote user can cause denial of service conditions.
|
Solution: The vendor has issued fixed development versions (2.0.61-dev and 2.2.6-dev).
|
Vendor URL: httpd.apache.org/ (Links to External Site)
|
Cause: Not specified
|
Underlying OS: Linux (Any), UNIX (Any), Windows (Any)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Thu, 30 Aug 2007 13:01:57 -0400
Subject: Apache httpd
|
2.0.61-dev
2.2.6-dev
mod_proxy crash CVE-2007-3847
|
|