PT-2007-4582 · Apache+1 · Apache Http Server+1

Published

2007-06-19

·

Updated

2024-06-15

·

CVE-2007-3304

CVSS v2.0

4.7

Medium

VectorAV:L/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Apache httpd versions 1.3.37, 2.0.59, and 2.2.4
Description The issue allows local users to cause a denial of service by modifying the worker score and process score arrays to reference an arbitrary process ID, which is sent a SIGUSR1 signal from the master process. This is possible because the Apache HTTP server does not verify that a process is an Apache child process before sending it signals. A local attacker with the ability to run scripts on the HTTP server could manipulate the scoreboard and cause arbitrary processes to be terminated, leading to a denial of service.
Recommendations For Apache httpd versions 1.3.37, 2.0.59, and 2.2.4, consider restricting access to the scoreboard and limiting the ability to run scripts on the HTTP server to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-3304
HPSBUX02273
OPENSUSE-SU-2024:10623-1
RHSA-2007:0532
RHSA-2007:0556
RHSA-2007:0557
RHSA-2007:0662
RHSA-2007_0556
RHSA-2007_0662
RHSA-2008:0261
RHSA-2008:0263
RHSA-2008:0523
RHSA-2008:0524
RHSA-2010:0602

Affected Products

Apache Http Server
Red Hat