PT-2007-3209 · Apache · Apache+1

Published

2007-06-01

·

Updated

2024-06-15

·

CVE-2007-1862

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Apache version 2.2.4
Description: The issue arises from the recall headers function in mod mem cache, which fails to properly copy all levels of header data. This can cause Apache to return HTTP headers containing previously used data, potentially allowing remote attackers to obtain sensitive information.
Recommendations: For Apache version 2.2.4, consider disabling the mod mem cache module until a patch is available to prevent the recall headers function from being exploited. Restrict access to sensitive information to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-1862
OPENSUSE-SU-2024:10623-1

Affected Products

Apache
Apache Http Server