The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a denial of service (caching forward proxy process crash) via crafted date headers that trigger a buffer over-read.

Project Subscriptions

Vendors Products
Http Server Subscribe
Canonical Subscribe
Ubuntu Linux Subscribe
Fedoraproject Subscribe
Fedora Core Subscribe
Certificate System Subscribe
Enterprise Linux Subscribe
Rhel Application Stack Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2007-3831 The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a denial of service (caching forward proxy process crash) via crafted date headers that trigger a buffer over-read.
Ubuntu USN Ubuntu USN USN-575-1 Apache vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
http://bugs.gentoo.org/show_bug.cgi?id=186219 cve-icon cve-icon
http://docs.info.apple.com/article.html?artnum=307562 cve-icon cve-icon
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01182588 cve-icon cve-icon
http://httpd.apache.org/security/vulnerabilities_20.html cve-icon cve-icon
http://httpd.apache.org/security/vulnerabilities_22.html cve-icon cve-icon
http://lists.apple.com/archives/security-announce/2008//May/msg00001.html cve-icon cve-icon
http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html cve-icon cve-icon
http://lists.vmware.com/pipermail/security-announce/2009/000062.html cve-icon cve-icon
http://marc.info/?l=apache-cvs&m=118592992309395&w=2 cve-icon cve-icon
http://marc.info/?l=apache-httpd-dev&m=118595556504202&w=2 cve-icon cve-icon
http://marc.info/?l=apache-httpd-dev&m=118595953217856&w=2 cve-icon cve-icon
http://secunia.com/advisories/26636 cve-icon cve-icon
http://secunia.com/advisories/26722 cve-icon cve-icon
http://secunia.com/advisories/26790 cve-icon cve-icon
http://secunia.com/advisories/26842 cve-icon cve-icon
http://secunia.com/advisories/26952 cve-icon cve-icon
http://secunia.com/advisories/26993 cve-icon cve-icon
http://secunia.com/advisories/27209 cve-icon cve-icon
http://secunia.com/advisories/27563 cve-icon cve-icon
http://secunia.com/advisories/27593 cve-icon cve-icon
http://secunia.com/advisories/27732 cve-icon cve-icon
http://secunia.com/advisories/27882 cve-icon cve-icon
http://secunia.com/advisories/27971 cve-icon cve-icon
http://secunia.com/advisories/28467 cve-icon cve-icon
http://secunia.com/advisories/28606 cve-icon cve-icon
http://secunia.com/advisories/28749 cve-icon cve-icon
http://secunia.com/advisories/28922 cve-icon cve-icon
http://secunia.com/advisories/29420 cve-icon cve-icon
http://secunia.com/advisories/30430 cve-icon cve-icon
http://security.gentoo.org/glsa/glsa-200711-06.xml cve-icon cve-icon
http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.595748 cve-icon cve-icon
http://support.avaya.com/elmodocs2/security/ASA-2007-500.htm cve-icon cve-icon
http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg27007951 cve-icon cve-icon
http://www-1.ibm.com/support/docview.wss?uid=swg1PK50469 cve-icon cve-icon
http://www-1.ibm.com/support/docview.wss?uid=swg1PK52702 cve-icon cve-icon
http://www.fujitsu.com/global/support/software/security/products-f/interstage-200802e.html cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2007:235 cve-icon cve-icon
http://www.novell.com/linux/security/advisories/2007_61_apache2.html cve-icon cve-icon
http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html cve-icon cve-icon
http://www.redhat.com/archives/fedora-package-announce/2007-September/msg00320.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2007-0746.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2007-0747.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2007-0911.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2008-0005.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/505990/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/25489 cve-icon cve-icon
http://www.securitytracker.com/id?1018633 cve-icon cve-icon
http://www.ubuntu.com/usn/usn-575-1 cve-icon cve-icon
http://www.us-cert.gov/cas/techalerts/TA08-150A.html cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/3020 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/3095 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/3283 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/3494 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/3955 cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/0233 cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/0924/references cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/1697 cve-icon cve-icon
https://issues.rpath.com/browse/RPL-1710 cve-icon cve-icon
https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r652fc951306cdeca5a276e2021a34878a76695a9f3cfb6490b4a6840%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/rafd145ba6cd0a4ced113a5823cdaff45aeb36eb09855b216401c66d6%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/reb542d2038e9c331506e0cbff881b47e40fbe2bd93ff00979e60cdf7%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2007-3847 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10525 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2007-3847 cve-icon
https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00353.html cve-icon cve-icon
History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-07T14:28:52.515Z

Reserved: 2007-07-18T04:00:00.000Z

Link: CVE-2007-3847

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2007-08-23T22:17:00.000

Modified: 2025-04-09T00:30:58.490

Link: CVE-2007-3847

cve-icon Redhat

Severity : Moderate

Publid Date: 2007-08-01T00:00:00Z

Links: CVE-2007-3847 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses