First published: Sat Jan 12 2008(Updated: )
** DISPUTED ** Unspecified vulnerability in mod_proxy_balancer for Apache HTTP Server 2.2.x before 2.2.7-dev, when running on Windows, allows remote attackers to trigger memory corruption via a long URL. NOTE: the vendor could not reproduce this issue.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Microsoft Windows NT | ||
Any of | ||
Apache Http Server | ||
Apache Http Server | =2.2.2 | |
Apache Http Server | =2.2.3 | |
Apache Http Server | =2.2.4 | |
Apache Http Server | =2.2.6 | |
Microsoft Windows NT | ||
Apache Http Server | ||
Apache Http Server | =2.2.2 | |
Apache Http Server | =2.2.3 | |
Apache Http Server | =2.2.4 | |
Apache Http Server | =2.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2007-6423 is currently disputed and unconfirmed by the vendor.
Updating to Apache HTTP Server version 2.2.7-dev or later is recommended to address CVE-2007-6423.
CVE-2007-6423 affects Apache HTTP Server versions 2.2.2, 2.2.3, 2.2.4, and 2.2.6 prior to 2.2.7-dev.
CVE-2007-6423 specifically occurs on Windows platforms.
Yes, CVE-2007-6423 can potentially be exploited remotely through long URLs.