5

CVE-2007-3847

The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a denial of service (caching forward proxy process crash) via crafted date headers that trigger a buffer over-read.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ApacheHTTP Server Version >= 2.0.35 < 2.0.61
ApacheHTTP Server Version >= 2.2.0 < 2.2.6
FedoraprojectFedora Version7
FedoraprojectFedora Core Version6
CanonicalUbuntu Linux Version6.06
CanonicalUbuntu Linux Version6.10
CanonicalUbuntu Linux Version7.04
CanonicalUbuntu Linux Version7.10
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 23.28% 0.959
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

http://www.us-cert.gov/cas/techalerts/TA08-150A.html
Third Party Advisory
US Government Resource
http://bugs.gentoo.org/show_bug.cgi?id=186219
Third Party Advisory
Issue Tracking
http://marc.info/?l=apache-cvs&m=118592992309395&w=2
Third Party Advisory
Mailing List
Issue Tracking
http://marc.info/?l=apache-httpd-dev&m=118595556504202&w=2
Third Party Advisory
Mailing List
Issue Tracking
http://marc.info/?l=apache-httpd-dev&m=118595953217856&w=2
Third Party Advisory
Mailing List
Issue Tracking
http://www.securityfocus.com/bid/25489
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id?1018633
Third Party Advisory
Broken Link
VDB Entry