CVE-1999-0107
published 1997-12-30CVE-1999-0107: Buffer overflow in Apache 1.2.5 and earlier allows a remote attacker to cause a denial of service with a large number of GET requests containing a large number…
PriorityP425medium5CVSS 2.0
AVNACLAuNCNINAP
EXPLOIT
EPSS
18.44%
96.9th percentile
Buffer overflow in Apache 1.2.5 and earlier allows a remote attacker to cause a denial of service with a large number of GET requests containing a large number of / characters.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect HTTP GET requests containing an abnormally large number of consecutive '/' characters in the request path, indicative of the Apache 1.2.x DoS exploit for CVE-1999-0107. ↗
- →Monitor for sustained CPU spikes on Apache web server processes coinciding with a high volume of GET requests, which may indicate exploitation of this buffer overflow/DoS vulnerability. ↗
- ·Affected versions are Apache 1.2.5 and earlier; systems running these versions are vulnerable. A service restart is required to recover normal functionality after exploitation. ↗
- ·Exploitation does not crash the service outright but causes CPU exhaustion; a manual restart of Apache is required to restore normal operation. ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
1997-12-30
Published