CVE-2007-6423
published 2008-01-12CVE-2007-6423: Unspecified vulnerability in mod_proxy_balancer for Apache HTTP Server 2.2.x before 2.2.7-dev, when running on Windows, allows remote attackers to trigger…
PriorityP431high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
3.90%
89.2th percentile
Unspecified vulnerability in mod_proxy_balancer for Apache HTTP Server 2.2.x before 2.2.7-dev, when running on Windows, allows remote attackers to trigger memory corruption via a long URL. NOTE: the vendor could not reproduce this issue
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| debian | apache2 | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_debian7.8LOW
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2007-6423: apache2 - Unspecified vulnerability in mod_proxy_balancer for Apache HTTP Server 2.2.x bef...
vendor_debian·2007·CVSS 7.8
CVE-2007-6423 [HIGH] CVE-2007-6423: apache2 - Unspecified vulnerability in mod_proxy_balancer for Apache HTTP Server 2.2.x bef...
Unspecified vulnerability in mod_proxy_balancer for Apache HTTP Server 2.2.x before 2.2.7-dev, when running on Windows, allows remote attackers to trigger memory corruption via a long URL. NOTE: the vendor could not reproduce this issue
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Red Hat
CVE-2007-6423: Unspecified vulnerability in mod_proxy_balancer for Apache HTTP Server 2
vendor_redhat·CVSS 7.8
CVE-2007-6423 [HIGH] CVE-2007-6423: Unspecified vulnerability in mod_proxy_balancer for Apache HTTP Server 2
Unspecified vulnerability in mod_proxy_balancer for Apache HTTP Server 2.2.x before 2.2.7-dev, when running on Windows, allows remote attackers to trigger memory corruption via a long URL. NOTE: the vendor could not reproduce this issue
Statement: mod_proxy_balancer is included in the version of Apache HTTP Server as shipped in Red Hat Enterprise Linux 5 and Red Hat Application Stack v2. Red Hat was unable to reproduce this issue.
GHSA
GHSA-f5gq-mm82-r92q: ** DISPUTED ** Unspecified vulnerability in mod_proxy_balancer for Apache HTTP Server 2
ghsa_unreviewed·2022-05-01
CVE-2007-6423 [HIGH] GHSA-f5gq-mm82-r92q: ** DISPUTED ** Unspecified vulnerability in mod_proxy_balancer for Apache HTTP Server 2
** DISPUTED ** Unspecified vulnerability in mod_proxy_balancer for Apache HTTP Server 2.2.x before 2.2.7-dev, when running on Windows, allows remote attackers to trigger memory corruption via a long URL. NOTE: the vendor could not reproduce this issue.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2008-01-12
Published