CVE-2007-3847
medium · 5The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a denial of service (caching forward proxy process crash) via crafted date headers that trigger a buffer over-read.
5
CVSS
12.9%
EPSS (exploit prob.)
96th
EPSS percentile
2007-08-23
Published
AV:N/AC:L/Au:N/C:N/I:N/A:P
Weaknesses
CWE-125
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apache | http_server | >= 2.0.35, < 2.0.61 |
| apache | http_server | >= 2.2.0, < 2.2.6 |
| fedoraproject | fedora | 7 |
| fedoraproject | fedora_core | 6 |
| canonical | ubuntu_linux | 6.06 |
| canonical | ubuntu_linux | 6.10 |
| canonical | ubuntu_linux | 7.04 |
| canonical | ubuntu_linux | 7.10 |
Check a specific version with /api/v1/cve/match.
References
- http://bugs.gentoo.org/show_bug.cgi?id=186219
- http://docs.info.apple.com/article.html?artnum=307562
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01182588
- http://httpd.apache.org/security/vulnerabilities_20.html
- http://httpd.apache.org/security/vulnerabilities_22.html
- http://lists.apple.com/archives/security-announce/2008//May/msg00001.html
- http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html
- http://lists.vmware.com/pipermail/security-announce/2009/000062.html
- http://marc.info/?l=apache-cvs&m=118592992309395&w=2
- http://marc.info/?l=apache-httpd-dev&m=118595556504202&w=2
- http://marc.info/?l=apache-httpd-dev&m=118595953217856&w=2
- http://secunia.com/advisories/26636
- http://secunia.com/advisories/26722
- http://secunia.com/advisories/26790
- http://secunia.com/advisories/26842
- http://secunia.com/advisories/26952
- http://secunia.com/advisories/26993
- http://secunia.com/advisories/27209
- http://secunia.com/advisories/27563
- http://secunia.com/advisories/27593
- http://secunia.com/advisories/27732
- http://secunia.com/advisories/27882
- http://secunia.com/advisories/27971
- http://secunia.com/advisories/28467
- http://secunia.com/advisories/28606
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2007-3847