CVE-2007-6422: Medium severity Apache HTTP Server vulnerability
Published Jan 8, 2008
·Updated
The balancerhandler function in modproxybalancer in the Apache HTTP Server 2.2.0 through 2.2.6, when a threaded Multi-Processing Module is used, allows remote authenticated users to cause a denial of service (child process crash) via an invalid bb variable.
Affected Software
7 affected components
Apache HTTP Server
Apache HTTP Server=2.2
Apache HTTP Server=2.2.1
Apache HTTP Server=2.2.2
Apache HTTP Server=2.2.3
Apache HTTP Server=2.2.4
Apache HTTP Server=2.2.6
Event History
Jan 8, 2008
CVE Published
06:46 PM
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-6422?
The severity of CVE-2007-6422 is considered to be medium, as it allows for denial of service through process crashes.
2
How do I fix CVE-2007-6422?
To fix CVE-2007-6422, upgrade Apache HTTP Server to version 2.2.7 or later.
3
What is affected by CVE-2007-6422?
CVE-2007-6422 affects Apache HTTP Server versions 2.2.0 through 2.2.6 when using a threaded Multi-Processing Module.
4
Can CVE-2007-6422 be exploited by unauthenticated users?
No, CVE-2007-6422 can only be exploited by remote authenticated users.
5
What does CVE-2007-6422 impact?
CVE-2007-6422 impacts the stability of the Apache HTTP Server by potentially crashing child processes.