CVE-2007-1863

Modified
Published: 27 Jun 2007, 17:00
Last modified:07 Aug 2024, 13:13

Vulnerability Summary

Overall Risk (default)
medium
26/100
CVSS Score
5 MEDIUM
v2.0 (nvd)
EPSS Score
27.99% HIGH
28% probability -4.31%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

27 Jun 2007, 17:00
Published
Vulnerability first disclosed
07 Aug 2024, 13:13
Last Modified
Vulnerability information updated

Description

cache_util.c in the mod_cache module in Apache HTTP Server (httpd), when caching is enabled and a threaded Multi-Processing Module (MPM) is used, allows remote attackers to cause a denial of service (child processing handler crash) via a request with the (1) s-maxage, (2) max-age, (3) min-fresh, or (4) max-stale Cache-Control headers without a value.

CVSS Metrics

  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 27.99% Percentile: 97%

Affected Systems

  • UnknownHTTP Server

    ≥ 2.0.37, < 2.0.61 | ≥ 2.2.0, < 2.2.6

  • applemac_os_x_server

    10.0 | 10.1 | 10.1.1 | 10.1.2 | 10.1.3 | 10.1.4 | 10.1.5 | 10.2 | 10.2.1 | 10.2.2 | 10.2.3 | 10.2.4 | 10.2.5 | 10.2.6 | 10.2.7 | 10.2.8 | 10.3 | 10.3.1 | 10.3.2 | 10.3.3 | 10.3.4 | 10.3.5 | 10.3.6 | 10.3.7 | 10.3.8 | 10.3.9 | 10.4 | 10.4.1 | 10.4.2 | 10.4.3 | 10.4.4 | 10.4.5 | 10.4.6 | 10.4.7 | 10.4.8 | 10.4.9

References (65)