← All CVEs

CVE-2007-3847

medium · 5

The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a denial of service (caching forward proxy process crash) via crafted date headers that trigger a buffer over-read.

5
CVSS
12.9%
EPSS (exploit prob.)
96th
EPSS percentile
2007-08-23
Published

AV:N/AC:L/Au:N/C:N/I:N/A:P

Weaknesses

CWE-125

Affected products

VendorProductAffected versions
apachehttp_server>= 2.0.35, < 2.0.61
apachehttp_server>= 2.2.0, < 2.2.6
fedoraprojectfedora7
fedoraprojectfedora_core6
canonicalubuntu_linux6.06
canonicalubuntu_linux6.10
canonicalubuntu_linux7.04
canonicalubuntu_linux7.10

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2007-3847