PT-2007-4582 · Apache+1 · Apache Http Server+1
Publicado
2007-06-19
·
Atualizado
2024-06-15
·
CVE-2007-3304
CVSS v2.0
4.7
Média
| Vetor | AV:L/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Apache httpd versions 1.3.37, 2.0.59, and 2.2.4
Description
The issue allows local users to cause a denial of service by modifying the
worker score and process score arrays to reference an arbitrary process ID, which is sent a SIGUSR1 signal from the master process. This is possible because the Apache HTTP server does not verify that a process is an Apache child process before sending it signals. A local attacker with the ability to run scripts on the HTTP server could manipulate the scoreboard and cause arbitrary processes to be terminated, leading to a denial of service.Recommendations
For Apache httpd versions 1.3.37, 2.0.59, and 2.2.4, consider restricting access to the scoreboard and limiting the ability to run scripts on the HTTP server to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Apache Http Server
Red Hat