PT-2011-1265 · Apache+2 · Apache Http Server+2
Published
2011-12-27
·
Updated
2026-03-10
·
CVE-2007-6750
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Apache HTTP Server versions 1.x through 2.x before 2.2.15
Description
The issue allows remote attackers to cause a denial of service, resulting in a daemon outage, via partial HTTP requests. This is related to the lack of the mod reqtimeout module in affected versions. The Slowloris tool has demonstrated this capability.
Recommendations
For Apache HTTP Server versions 1.x through 2.x before 2.2.15, update to version 2.2.15 or later to resolve the issue. As a temporary workaround, consider enabling the mod reqtimeout module to mitigate the risk of denial of service attacks.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Http Server
Hp-Ux
Suse