CVE-2007-3847

Description

The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a denial of service (caching forward proxy process crash) via crafted date headers that trigger a buffer over-read.

Risk Information

Base Score
9.8
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
22.605

Associated Vulnerability

VulnerabilityOS Platform
Update Apache to version 2.2.3Windows
Update Apache to version 2.0.61Windows
Vulnerabilities CVE-2007-3847 are fixed in Apache 2.2.6Windows
Vulnerabilities CVE-2007-3847 are fixed in Apache 2.0.61Windows
Multiple vulnerabilities are affected in Oracle HTTP Server 5.0Windows
Update Apache to version 2.2.3 (For Linux)Linux
Update Apache to version 2.0.61 (For Linux)Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234