CVE-2007-3847: Medium severity Apache HTTP Server vulnerability
The date handling code in modules/proxy/proxyutil.c (modproxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a denial of service (caching forward proxy process crash) via crafted date headers that trigger a buffer over-read.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-3847?
CVE-2007-3847 has a severity rating that indicates it can lead to a denial of service due to a crashing process.
How do I fix CVE-2007-3847?
To fix CVE-2007-3847, upgrade to a patched version of Apache HTTP Server that addresses this vulnerability.
What systems are affected by CVE-2007-3847?
CVE-2007-3847 affects Apache HTTP Server versions 2.3.0 and earlier, as well as certain versions of Fedora and Ubuntu.
Can CVE-2007-3847 be exploited remotely?
Yes, CVE-2007-3847 can be exploited remotely by sending crafted date headers to the affected server.
What are the consequences of CVE-2007-3847?
The primary consequence of CVE-2007-3847 is a denial of service that causes the caching forward proxy process to crash.