CVE-2007-6423: High severity Microsoft Windows NT vulnerability
Published Jan 12, 2008
·Updated
DISPUTED Unspecified vulnerability in modproxybalancer for Apache HTTP Server 2.2.x before 2.2.7-dev, when running on Windows, allows remote attackers to trigger memory corruption via a long URL. NOTE: the vendor could not reproduce this issue.
Affected Software
12 affected components
All of the following
Microsoft Windows NT
Any of the following
Apache HTTP Server
Apache HTTP Server=2.2.2
Apache HTTP Server=2.2.3
Apache HTTP Server=2.2.4
Apache HTTP Server=2.2.6
Microsoft Windows NT
Apache HTTP Server
Apache HTTP Server=2.2.2
Apache HTTP Server=2.2.3
Apache HTTP Server=2.2.4
Apache HTTP Server=2.2.6
Event History
Jan 12, 2008
CVE Published
12:46 AM
Disputed
12:46 AM
Data Sourced
12:46 AM
DescriptionWeaknessAffected Software
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-6423?
The severity of CVE-2007-6423 is currently disputed and unconfirmed by the vendor.
2
How do I fix CVE-2007-6423?
Updating to Apache HTTP Server version 2.2.7-dev or later is recommended to address CVE-2007-6423.
3
Which versions of Apache HTTP Server are affected by CVE-2007-6423?
CVE-2007-6423 affects Apache HTTP Server versions 2.2.2, 2.2.3, 2.2.4, and 2.2.6 prior to 2.2.7-dev.
4
On which operating system does CVE-2007-6423 occur?
CVE-2007-6423 specifically occurs on Windows platforms.
5
Can CVE-2007-6423 be exploited remotely?
Yes, CVE-2007-6423 can potentially be exploited remotely through long URLs.