PT-2011-1265 · Apache+2 · Apache Http Server+2

Published

2011-12-27

·

Updated

2026-03-10

·

CVE-2007-6750

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 1.x through 2.x before 2.2.15
Description The issue allows remote attackers to cause a denial of service, resulting in a daemon outage, via partial HTTP requests. This is related to the lack of the mod reqtimeout module in affected versions. The Slowloris tool has demonstrated this capability.
Recommendations For Apache HTTP Server versions 1.x through 2.x before 2.2.15, update to version 2.2.15 or later to resolve the issue. As a temporary workaround, consider enabling the mod reqtimeout module to mitigate the risk of denial of service attacks.

Exploit

Fix

DoS

Weakness Enumeration

Related Identifiers

CVE-2007-6750
HPSBUX02866
OPENSUSE-SU-2012_0314-1
SUSE-SU-2012_0284-1
SUSE-SU-2012_0323-1

Affected Products

Apache Http Server
Hp-Ux
Suse