CVE-2007-0086Uncontrolled Resource Consumption in Apache Http Server

Severity
7.8HIGHNVD
EPSS
3.3%
top 12.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 5
Latest updateMay 13

Description

The Apache HTTP Server, when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same fragment. NOTE: the severity of this issue has been disputed by third parties, who state that the large window size required by the attack is not normally supported or configured by the server, or that a DDoS-style attack would accomplish the same goal

CVSS vector

AV:N/AC:L/C:N/I:N/A:CExploitability: 10.0 | Impact: 6.9

Affected Packages10 packages

NVDapache/http_server2.0.352.0.65+1
debiandebian/apache2< apache2 2.2.19-2 (bookworm)+1
NVDopensuse/opensuse11.3, 11.4+1

Also affects: Ubuntu Linux 10.04, 10.10, 11.04, 8.04

🔴Vulnerability Details

5
GHSA
GHSA-r3pv-69hm-fcjw: The byterange filter in the Apache HTTP Server 12022-05-13
GHSA
GHSA-vfvv-gfh6-h8qc: ** DISPUTED ** The Apache HTTP Server, when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of s2022-05-01
OSV
CVE-2011-3192: The byterange filter in the Apache HTTP Server 12011-08-29
VulnCheck
Apache HTTP Server Uncontrolled Resource Consumption2011
OSV
CVE-2007-0086: The Apache HTTP Server, when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network2007-01-05

📋Vendor Advisories

5
Microsoft
CVE-2007-0086: NIST NVD Details: https://nvd2020-09-08
Red Hat
httpd: multiple ranges DoS2011-08-20
Debian
CVE-2011-3192: apache2 - The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and ...2011
Debian
CVE-2007-0086: apache2 - The Apache HTTP Server, when accessed through a TCP connection with a large wind...2007
Red Hat
CVE-2007-0086: The Apache HTTP Server, when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network

💬Community

1
HackerOne
Out-of-date Version (Apache)2019-12-02