PT-2007-4582 · Apache+1 · Apache Http Server+1

Publicado

2007-06-19

·

Atualizado

2024-06-15

·

CVE-2007-3304

CVSS v2.0

4.7

Média

VetorAV:L/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Apache httpd versions 1.3.37, 2.0.59, and 2.2.4
Description The issue allows local users to cause a denial of service by modifying the worker score and process score arrays to reference an arbitrary process ID, which is sent a SIGUSR1 signal from the master process. This is possible because the Apache HTTP server does not verify that a process is an Apache child process before sending it signals. A local attacker with the ability to run scripts on the HTTP server could manipulate the scoreboard and cause arbitrary processes to be terminated, leading to a denial of service.
Recommendations For Apache httpd versions 1.3.37, 2.0.59, and 2.2.4, consider restricting access to the scoreboard and limiting the ability to run scripts on the HTTP server to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-3304
HPSBUX02273
OPENSUSE-SU-2024:10623-1
RHSA-2007:0532
RHSA-2007:0556
RHSA-2007:0557
RHSA-2007:0662
RHSA-2007_0556
RHSA-2007_0662
RHSA-2008:0261
RHSA-2008:0263
RHSA-2008:0523
RHSA-2008:0524
RHSA-2010:0602

Produtos afetados

Apache Http Server
Red Hat