CVE-2007-3304

Description

Apache httpd 1.3.37, 2.0.59, and 2.2.4 with the Prefork MPM module, allows local users to cause a denial of service by modifying the worker_score and process_score arrays to reference an arbitrary process ID, which is sent a SIGUSR1 signal from the master process, aka SIGUSR1 killer.

Risk Information

Base Score
6.3
MODERATE
Vector
AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.098

Associated Vulnerability

VulnerabilityOS Platform
Update Apache to version 2.2.3Windows
Update Apache to version 2.0.61Windows
Update Apache to version 1.3.37Windows
Vulnerabilities CVE-2007-3304 are fixed in Apache 2.2.6Windows
Vulnerabilities CVE-2007-3304 are fixed in Apache 2.0.61Windows
Vulnerabilities CVE-2007-3304 are fixed in Apache 1.3.39Windows
Update Apache to version 2.2.3 (For Linux)Linux
Update Apache to version 2.0.61 (For Linux)Linux
Update Apache to version 1.3.37 (For Linux)Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234