PT-2007-3209 · Apache · Apache+1

Publicado

2007-06-01

·

Atualizado

2024-06-15

·

CVE-2007-1862

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Apache version 2.2.4
Description: The issue arises from the recall headers function in mod mem cache, which fails to properly copy all levels of header data. This can cause Apache to return HTTP headers containing previously used data, potentially allowing remote attackers to obtain sensitive information.
Recommendations: For Apache version 2.2.4, consider disabling the mod mem cache module until a patch is available to prevent the recall headers function from being exploited. Restrict access to sensitive information to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-1862
OPENSUSE-SU-2024:10623-1

Produtos afetados

Apache
Apache Http Server