PT-2008-1555 · Apache+1 · Apache Http Server+1
Published
2008-01-02
·
Updated
2024-06-15
·
CVE-2007-6422
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Apache HTTP Server versions 2.2.0 through 2.2.6
Description
A flaw in the mod proxy balancer module allows remote authenticated users to cause a denial of service, resulting in a child process crash, when a threaded Multi-Processing Module is used. This can be achieved by sending a carefully crafted request with an invalid
bb variable.Recommendations
For Apache HTTP Server versions 2.2.0 through 2.2.6, consider disabling the
balancer handler function in the mod proxy balancer module as a temporary workaround to prevent exploitation. Restrict access to the mod proxy balancer module to minimize the risk of denial of service attacks. Avoid using the bb variable in requests to the affected module until the issue is resolved.Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Http Server
Red Hat