Vulnerability Description
cache_util.c in the mod_cache module in Apache HTTP Server (httpd), when caching is enabled and a threaded Multi-Processing Module (MPM) is used, allows remote attackers to cause a denial of service (child processing handler crash) via a request with the (1) s-maxage, (2) max-age, (3) min-fresh, or (4) max-stale Cache-Control headers without a value.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | Mac Os X Server | 10.0 |
| Apache | Http Server | >= 2.0.37, < 2.0.61 |
References
- http://bugs.gentoo.org/show_bug.cgi?id=186219Third Party Advisory
- http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=244658Issue Tracking
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795Broken Link
- http://httpd.apache.org/security/vulnerabilities_20.htmlVendor Advisory
- http://httpd.apache.org/security/vulnerabilities_22.htmlVendor Advisory
- http://lists.apple.com/archives/security-announce/2008//May/msg00001.htmlThird Party Advisory
- http://lists.vmware.com/pipermail/security-announce/2009/000062.htmlThird Party AdvisoryVDB Entry
- http://osvdb.org/37079Broken Link
- http://rhn.redhat.com/errata/RHSA-2007-0534.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2007-0556.htmlThird Party AdvisoryVDB Entry
- http://secunia.com/advisories/25830Broken Link
- http://secunia.com/advisories/25873Broken Link
- http://secunia.com/advisories/25920Broken Link
- http://secunia.com/advisories/26273Broken Link
- http://secunia.com/advisories/26443Broken Link
FAQ
What is CVE-2007-1863?
CVE-2007-1863 is a vulnerability with a CVSS score of 5.0 (MEDIUM). cache_util.c in the mod_cache module in Apache HTTP Server (httpd), when caching is enabled and a threaded Multi-Processing Module (MPM) is used, allows remote attackers to cause a denial of service (...
How severe is CVE-2007-1863?
CVE-2007-1863 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-1863?
Check the references section above for vendor advisories and patch information. Affected products include: Apple Mac Os X Server, Apache Http Server.