PT-2008-1555 · Apache+1 · Apache Http Server+1

Published

2008-01-02

·

Updated

2024-06-15

·

CVE-2007-6422

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.2.0 through 2.2.6
Description A flaw in the mod proxy balancer module allows remote authenticated users to cause a denial of service, resulting in a child process crash, when a threaded Multi-Processing Module is used. This can be achieved by sending a carefully crafted request with an invalid bb variable.
Recommendations For Apache HTTP Server versions 2.2.0 through 2.2.6, consider disabling the balancer handler function in the mod proxy balancer module as a temporary workaround to prevent exploitation. Restrict access to the mod proxy balancer module to minimize the risk of denial of service attacks. Avoid using the bb variable in requests to the affected module until the issue is resolved.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-6422
OPENSUSE-SU-2024:10623-1
RHSA-2008:0008
RHSA-2008:0009
RHSA-2008_0008

Affected Products

Apache Http Server
Red Hat