CVE-2007-3303
published 2007-06-20CVE-2007-3303: Apache httpd 2.0.59 and 2.2.4, with the Prefork MPM module, allows local users to cause a denial of service via certain code sequences executed in a worker…
PriorityP412medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.89%
55.7th percentile
Apache httpd 2.0.59 and 2.2.4, with the Prefork MPM module, allows local users to cause a denial of service via certain code sequences executed in a worker process that (1) stop request processing by killing all worker processes and preventing creation of replacements or (2) hang the system by forcing the master process to fork an arbitrarily large number of worker processes. NOTE: This might be an inherent design limitation of Apache with respect to worker processes in hosted environments.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | — | — |
| apache | http_server | — | — |
| debian | apache2 | — | — |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv4.9MEDIUM
vendor_debian4.9LOW
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hxj5-ccfq-hvjx: Apache httpd 2
ghsa_unreviewed·2022-05-01
CVE-2007-3303 [MEDIUM] CWE-94 GHSA-hxj5-ccfq-hvjx: Apache httpd 2
Apache httpd 2.0.59 and 2.2.4, with the Prefork MPM module, allows local users to cause a denial of service via certain code sequences executed in a worker process that (1) stop request processing by killing all worker processes and preventing creation of replacements or (2) hang the system by forcing the master process to fork an arbitrarily large number of worker processes. NOTE: This might be an inherent design limitation of Apache with respect to worker processes in hosted environments.
OSV
CVE-2007-3303: Apache httpd 2
osv·2007-06-20·CVSS 4.9
CVE-2007-3303 [MEDIUM] CVE-2007-3303: Apache httpd 2
Apache httpd 2.0.59 and 2.2.4, with the Prefork MPM module, allows local users to cause a denial of service via certain code sequences executed in a worker process that (1) stop request processing by killing all worker processes and preventing creation of replacements or (2) hang the system by forcing the master process to fork an arbitrarily large number of worker processes. NOTE: This might be an inherent design limitation of Apache with respect to worker processes in hosted environments.
Debian
CVE-2007-3303: apache2 - Apache httpd 2.0.59 and 2.2.4, with the Prefork MPM module, allows local users t...
vendor_debian·2007·CVSS 4.9
CVE-2007-3303 [MEDIUM] CVE-2007-3303: apache2 - Apache httpd 2.0.59 and 2.2.4, with the Prefork MPM module, allows local users t...
Apache httpd 2.0.59 and 2.2.4, with the Prefork MPM module, allows local users to cause a denial of service via certain code sequences executed in a worker process that (1) stop request processing by killing all worker processes and preventing creation of replacements or (2) hang the system by forcing the master process to fork an arbitrarily large number of worker processes. NOTE: This might be an inherent design limitation of Apache with respect to worker processes in hosted environments.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
Red Hat
CVE-2007-3303: Apache httpd 2
vendor_redhat·CVSS 4.9
CVE-2007-3303 [MEDIUM] CVE-2007-3303: Apache httpd 2
Apache httpd 2.0.59 and 2.2.4, with the Prefork MPM module, allows local users to cause a denial of service via certain code sequences executed in a worker process that (1) stop request processing by killing all worker processes and preventing creation of replacements or (2) hang the system by forcing the master process to fork an arbitrarily large number of worker processes. NOTE: This might be an inherent design limitation of Apache with respect to worker processes in hosted environments.
Statement: Not a vulnerability. In the security model used by Apache httpd, the less-privileged child processes (running as the "apache" user) completely handle the servicing of new connections. Any local user who is able to run arbitrary code in those children is therefore able to prevent new requests
No detection rules found.
No public exploits indexed.
http://osvdb.org/37050http://security.psnc.pl/files/apache_report.pdfhttp://securityreason.com/securityalert/2814http://www.securityfocus.com/archive/1/469899/100/0/threadedhttp://www.securityfocus.com/archive/1/471832/100/0/threadedhttp://www.securityfocus.com/bid/24215http://osvdb.org/37050http://security.psnc.pl/files/apache_report.pdfhttp://securityreason.com/securityalert/2814http://www.securityfocus.com/archive/1/469899/100/0/threadedhttp://www.securityfocus.com/archive/1/471832/100/0/threadedhttp://www.securityfocus.com/bid/24215
2007-06-20
Published