CVE-2007-3847
published 2007-08-23CVE-2007-3847: The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a denial of…
PriorityP425medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
12.90%
95.9th percentile
The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a denial of service (caching forward proxy process crash) via crafted date headers that trigger a buffer over-read.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | >= 2.0.35 < 2.0.61 | 2.0.61 |
| apache | http_server | >= 2.2.0 < 2.2.6 | 2.2.6 |
| apache | httpd | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | apache2 | < apache2 2.2.6-1 (bookworm) | apache2 2.2.6-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora_core | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_apache5.0
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Apache vulnerabilities
vendor_ubuntu·2008-02-04·CVSS 4.3
CVE-2006-3918 [MEDIUM] Apache vulnerabilities
Title: Apache vulnerabilities
Summary: Apache vulnerabilities
It was discovered that Apache did not sanitize the Expect header from
an HTTP request when it is reflected back in an error message, which
could result in browsers becoming vulnerable to cross-site scripting
attacks when processing the output. With cross-site scripting
vulnerabilities, if a user were tricked into viewing server output
during a crafted server request, a remote attacker could exploit this
to modify the contents, or steal confidential data (such as passwords),
within the same domain. This was only vulnerable in Ubuntu 6.06.
(CVE-2006-3918)
It was discovered that when configured as a proxy server and using a
threaded MPM, Apache did not properly sanitize its input. A remote
attacker could send Apache crafted date
Red Hat
httpd: out of bounds read
vendor_redhat·2007-08-01·CVSS 5.0
CVE-2007-3847 [MEDIUM] CWE-125 httpd: out of bounds read
httpd: out of bounds read
The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a denial of service (caching forward proxy process crash) via crafted date headers that trigger a buffer over-read.
Debian
CVE-2007-3847: apache2 - The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0...
vendor_debian·2007·CVSS 5.0
CVE-2007-3847 [MEDIUM] CVE-2007-3847: apache2 - The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0...
The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a denial of service (caching forward proxy process crash) via crafted date headers that trigger a buffer over-read.
Scope: local
bookworm: resolved (fixed in 2.2.6-1)
bullseye: resolved (fixed in 2.2.6-1)
forky: resolved (fixed in 2.2.6-1)
sid: resolved (fixed in 2.2.6-1)
trixie: resolved (fixed in 2.2.6-1)
Apache
Apache httpd: CVE-2007-3847
vendor_apache·CVSS 5.0
CVE-2007-3847 Apache httpd: CVE-2007-3847
Apache httpd: CVE-2007-3847
A flaw was found in the Apache HTTP Server mod_proxy module. On sites where a reverse proxy is configured, a remote attacker could send a carefully crafted request that would cause the Apache child process handling that request to crash. On sites where a forward proxy is configured, an attacker could cause a similar crash if a user could be persuaded to visit a malicious site using the proxy. This could lead to a denial of service if using a threaded Multi-Processing Module. Reported to security team 2006-12-10 Issue public 2006-12-10 Update 2.2.6 released 2007-09-07 Update 2.0.61 released 2007-09-07 Affects 2.2.4, 2.2.3, 2.2.2, 2.2.0, 2.0.59, 2.0.58, 2.0.55, 2.0.54, 2.0.53, 2.0.52, 2.0.51, 2.0.50, 2.0.49, 2.0.48, 2.0.47, 2.0.46, 2.0.45, 2.0.44, 2.0.43, 2.0.42,
GHSA
GHSA-v7h4-gr67-jxvj: The date handling code in modules/proxy/proxy_util
ghsa_unreviewed·2022-05-01
CVE-2007-3847 [MEDIUM] CWE-125 GHSA-v7h4-gr67-jxvj: The date handling code in modules/proxy/proxy_util
The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a denial of service (caching forward proxy process crash) via crafted date headers that trigger a buffer over-read.
OSV
CVE-2007-3847: The date handling code in modules/proxy/proxy_util
osv·2007-08-23·CVSS 5.0
CVE-2007-3847 [MEDIUM] CVE-2007-3847: The date handling code in modules/proxy/proxy_util
The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a denial of service (caching forward proxy process crash) via crafted date headers that trigger a buffer over-read.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-3847 httpd out of bounds read [FC6]
bugzilla·2007-08-03·CVSS 5.0
CVE-2007-3847 [MEDIUM] CVE-2007-3847 httpd out of bounds read [FC6]
CVE-2007-3847 httpd out of bounds read [FC6]
FC6 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
Fedora apologizes that these issues have not been resolved yet. We're
sorry it's taken so long for your bug to be properly triaged and acted
on. We appreciate the time you took to report this issue and want to
make sure no important bugs slip through the cracks.
If you're currently running a version of Fedora Core between 1 and 6,
please note that Fedora no longer maintains these releases. We strongly
encourage you to upgrade to a current Fedora release. In order to
refocus our efforts as a project we are flagging all of the open bugs
for releases which are no longer maintained and closing them.
htt
Bugzilla
CVE-2007-3847 httpd: out of bounds read
bugzilla·2007-08-03·CVSS 5.0
CVE-2007-3847 [MEDIUM] CVE-2007-3847 httpd: out of bounds read
CVE-2007-3847 httpd: out of bounds read
A buffer "over-read" flaw was found in Apache httpd used for caching. This
allows a malicious origin server to possibly cause a process crash on a caching
forward proxy, which is a DoS for a threaded MPM on httpd 2.0+
On httpd 1.3 this would cause a client crash but this is not considered a
security issue as httpd would continue to run and spawn new children as required.
http://marc.info/?l=apache-httpd-dev&m=118595556504202&w=2
Discussion:
This issue has been addressed in following products:
Red Hat Certificate System 7.3
Via RHSA-2010:0602 https://rhn.redhat.com/errata/RHSA-2010-0602.html
Bugzilla
CVE-2007-3847 httpd out of bounds read [F7]
bugzilla·2007-08-03·CVSS 5.0
CVE-2007-3847 [MEDIUM] CVE-2007-3847 httpd out of bounds read [F7]
CVE-2007-3847 httpd out of bounds read [F7]
F7 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
httpd-2.2.6-1.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2007-3847 httpd out of bounds read [Fdevel]
bugzilla·2007-08-03·CVSS 5.0
CVE-2007-3847 [MEDIUM] CVE-2007-3847 httpd out of bounds read [Fdevel]
CVE-2007-3847 httpd out of bounds read [Fdevel]
Fdevel tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
httpd 2.2.6 will fix this issue.
---
Fixed with 2.2.6 upgrade.
http://bugs.gentoo.org/show_bug.cgi?id=186219http://docs.info.apple.com/article.html?artnum=307562http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01182588http://httpd.apache.org/security/vulnerabilities_20.htmlhttp://httpd.apache.org/security/vulnerabilities_22.htmlhttp://lists.apple.com/archives/security-announce/2008//May/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2008/Mar/msg00001.htmlhttp://lists.vmware.com/pipermail/security-announce/2009/000062.htmlhttp://marc.info/?l=apache-cvs&m=118592992309395&w=2http://marc.info/?l=apache-httpd-dev&m=118595556504202&w=2http://marc.info/?l=apache-httpd-dev&m=118595953217856&w=2http://secunia.com/advisories/26636http://secunia.com/advisories/26722http://secunia.com/advisories/26790http://secunia.com/advisories/26842http://secunia.com/advisories/26952http://secunia.com/advisories/26993http://secunia.com/advisories/27209http://secunia.com/advisories/27563http://secunia.com/advisories/27593http://secunia.com/advisories/27732http://secunia.com/advisories/27882http://secunia.com/advisories/27971http://secunia.com/advisories/28467http://secunia.com/advisories/28606http://secunia.com/advisories/28749http://secunia.com/advisories/28922http://secunia.com/advisories/29420http://secunia.com/advisories/30430http://security.gentoo.org/glsa/glsa-200711-06.xmlhttp://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.595748http://support.avaya.com/elmodocs2/security/ASA-2007-500.htmhttp://www-1.ibm.com/support/docview.wss?rs=180&uid=swg27007951http://www-1.ibm.com/support/docview.wss?uid=swg1PK50469http://www-1.ibm.com/support/docview.wss?uid=swg1PK52702http://www.fujitsu.com/global/support/software/security/products-f/interstage-200802e.htmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2007:235http://www.novell.com/linux/security/advisories/2007_61_apache2.htmlhttp://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.htmlhttp://www.redhat.com/archives/fedora-package-announce/2007-September/msg00320.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0746.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0747.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0911.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0005.htmlhttp://www.securityfocus.com/archive/1/505990/100/0/threadedhttp://www.securityfocus.com/bid/25489http://www.securitytracker.com/id?1018633http://www.ubuntu.com/usn/usn-575-1http://www.us-cert.gov/cas/techalerts/TA08-150A.htmlhttp://www.vupen.com/english/advisories/2007/3020http://www.vupen.com/english/advisories/2007/3095http://www.vupen.com/english/advisories/2007/3283http://www.vupen.com/english/advisories/2007/3494http://www.vupen.com/english/advisories/2007/3955http://www.vupen.com/english/advisories/2008/0233http://www.vupen.com/english/advisories/2008/0924/referenceshttp://www.vupen.com/english/advisories/2008/1697https://issues.rpath.com/browse/RPL-1710https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r652fc951306cdeca5a276e2021a34878a76695a9f3cfb6490b4a6840%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rafd145ba6cd0a4ced113a5823cdaff45aeb36eb09855b216401c66d6%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/reb542d2038e9c331506e0cbff881b47e40fbe2bd93ff00979e60cdf7%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3Ehttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10525https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00353.htmlhttp://bugs.gentoo.org/show_bug.cgi?id=186219http://docs.info.apple.com/article.html?artnum=307562http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01182588http://httpd.apache.org/security/vulnerabilities_20.htmlhttp://httpd.apache.org/security/vulnerabilities_22.htmlhttp://lists.apple.com/archives/security-announce/2008//May/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2008/Mar/msg00001.htmlhttp://lists.vmware.com/pipermail/security-announce/2009/000062.htmlhttp://marc.info/?l=apache-cvs&m=118592992309395&w=2http://marc.info/?l=apache-httpd-dev&m=118595556504202&w=2http://marc.info/?l=apache-httpd-dev&m=118595953217856&w=2http://secunia.com/advisories/26636http://secunia.com/advisories/26722http://secunia.com/advisories/26790http://secunia.com/advisories/26842http://secunia.com/advisories/26952http://secunia.com/advisories/26993http://secunia.com/advisories/27209
+ 64 more references
2007-08-23
Published