PT-2007-3209 · Apache · Apache+1
Published
2007-06-01
·
Updated
2024-06-15
·
CVE-2007-1862
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Apache version 2.2.4
Description:
The issue arises from the recall headers function in mod mem cache, which fails to properly copy all levels of header data. This can cause Apache to return HTTP headers containing previously used data, potentially allowing remote attackers to obtain sensitive information.
Recommendations:
For Apache version 2.2.4, consider disabling the mod mem cache module until a patch is available to prevent the recall headers function from being exploited. Restrict access to sensitive information to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache
Apache Http Server