PT-2008-1555 · Apache+1 · Apache Http Server+1

Publicado

2008-01-02

·

Atualizado

2024-06-15

·

CVE-2007-6422

CVSS v2.0

4.0

Média

VetorAV:N/AC:L/Au:S/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.2.0 through 2.2.6
Description A flaw in the mod proxy balancer module allows remote authenticated users to cause a denial of service, resulting in a child process crash, when a threaded Multi-Processing Module is used. This can be achieved by sending a carefully crafted request with an invalid bb variable.
Recommendations For Apache HTTP Server versions 2.2.0 through 2.2.6, consider disabling the balancer handler function in the mod proxy balancer module as a temporary workaround to prevent exploitation. Restrict access to the mod proxy balancer module to minimize the risk of denial of service attacks. Avoid using the bb variable in requests to the affected module until the issue is resolved.

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-6422
OPENSUSE-SU-2024:10623-1
RHSA-2008:0008
RHSA-2008:0009
RHSA-2008_0008

Produtos afetados

Apache Http Server
Red Hat