CVE-2007-6422
published 2008-01-08CVE-2007-6422: The balancer_handler function in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6, when a threaded Multi-Processing Module is used, allows…
PriorityP417medium4CVSS 2.0
AVNACLAuSCNINAP
EPSS
9.95%
95.1th percentile
The balancer_handler function in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6, when a threaded Multi-Processing Module is used, allows remote authenticated users to cause a denial of service (child process crash) via an invalid bb variable.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| debian | apache2 | < apache2 2.2.8-1 (bookworm) | apache2 2.2.8-1 (bookworm) |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv4.0MEDIUM
vendor_ubuntu4.3MEDIUM
vendor_debian4.0LOW
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Apache vulnerabilities
vendor_ubuntu·2008-02-04·CVSS 4.3
CVE-2006-3918 [MEDIUM] Apache vulnerabilities
Title: Apache vulnerabilities
Summary: Apache vulnerabilities
It was discovered that Apache did not sanitize the Expect header from
an HTTP request when it is reflected back in an error message, which
could result in browsers becoming vulnerable to cross-site scripting
attacks when processing the output. With cross-site scripting
vulnerabilities, if a user were tricked into viewing server output
during a crafted server request, a remote attacker could exploit this
to modify the contents, or steal confidential data (such as passwords),
within the same domain. This was only vulnerable in Ubuntu 6.06.
(CVE-2006-3918)
It was discovered that when configured as a proxy server and using a
threaded MPM, Apache did not properly sanitize its input. A remote
attacker could send Apache crafted date
Red Hat
httpd mod_proxy_balancer crash
vendor_redhat·2008-01-01·CVSS 4.0
CVE-2007-6422 [MEDIUM] httpd mod_proxy_balancer crash
httpd mod_proxy_balancer crash
The balancer_handler function in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6, when a threaded Multi-Processing Module is used, allows remote authenticated users to cause a denial of service (child process crash) via an invalid bb variable.
Debian
CVE-2007-6422: apache2 - The balancer_handler function in mod_proxy_balancer in the Apache HTTP Server 2....
vendor_debian·2007·CVSS 4.0
CVE-2007-6422 [MEDIUM] CVE-2007-6422: apache2 - The balancer_handler function in mod_proxy_balancer in the Apache HTTP Server 2....
The balancer_handler function in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6, when a threaded Multi-Processing Module is used, allows remote authenticated users to cause a denial of service (child process crash) via an invalid bb variable.
Scope: local
bookworm: resolved (fixed in 2.2.8-1)
bullseye: resolved (fixed in 2.2.8-1)
forky: resolved (fixed in 2.2.8-1)
sid: resolved (fixed in 2.2.8-1)
trixie: resolved (fixed in 2.2.8-1)
GHSA
GHSA-qmrc-358m-f76x: The balancer_handler function in mod_proxy_balancer in the Apache HTTP Server 2
ghsa_unreviewed·2022-05-01
CVE-2007-6422 [MEDIUM] GHSA-qmrc-358m-f76x: The balancer_handler function in mod_proxy_balancer in the Apache HTTP Server 2
The balancer_handler function in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6, when a threaded Multi-Processing Module is used, allows remote authenticated users to cause a denial of service (child process crash) via an invalid bb variable.
OSV
CVE-2007-6422: The balancer_handler function in mod_proxy_balancer in the Apache HTTP Server 2
osv·2008-01-08·CVSS 4.0
CVE-2007-6422 [MEDIUM] CVE-2007-6422: The balancer_handler function in mod_proxy_balancer in the Apache HTTP Server 2
The balancer_handler function in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6, when a threaded Multi-Processing Module is used, allows remote authenticated users to cause a denial of service (child process crash) via an invalid bb variable.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://httpd.apache.org/security/vulnerabilities_22.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-04/msg00004.htmlhttp://secunia.com/advisories/28526http://secunia.com/advisories/28749http://secunia.com/advisories/28977http://secunia.com/advisories/29348http://secunia.com/advisories/29640http://security.gentoo.org/glsa/glsa-200803-19.xmlhttp://securityreason.com/securityalert/3523http://www.mandriva.com/security/advisories?name=MDVSA-2008:016http://www.redhat.com/support/errata/RHSA-2008-0008.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0009.htmlhttp://www.securityfocus.com/archive/1/486169/100/0/threadedhttp://www.securityfocus.com/bid/27236http://www.ubuntu.com/usn/usn-575-1http://www.vupen.com/english/advisories/2008/0048https://exchange.xforce.ibmcloud.com/vulnerabilities/39476https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3Ehttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10181https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8690https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00541.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-February/msg00562.htmlhttp://httpd.apache.org/security/vulnerabilities_22.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-04/msg00004.htmlhttp://secunia.com/advisories/28526http://secunia.com/advisories/28749http://secunia.com/advisories/28977http://secunia.com/advisories/29348http://secunia.com/advisories/29640http://security.gentoo.org/glsa/glsa-200803-19.xmlhttp://securityreason.com/securityalert/3523http://www.mandriva.com/security/advisories?name=MDVSA-2008:016http://www.redhat.com/support/errata/RHSA-2008-0008.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0009.htmlhttp://www.securityfocus.com/archive/1/486169/100/0/threadedhttp://www.securityfocus.com/bid/27236http://www.ubuntu.com/usn/usn-575-1http://www.vupen.com/english/advisories/2008/0048https://exchange.xforce.ibmcloud.com/vulnerabilities/39476https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3Ehttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10181https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8690https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00541.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-February/msg00562.html
2008-01-08
Published