CVE-2007-1863

UnknownEPSS 11.79%

Last modified

CVE-2007-1863 is a vulnerability of currently unknown severity. cache_util.c in the mod_cache module in Apache HTTP Server (httpd), when caching is enabled and a threaded Multi-Processing Module (MPM) is used, allows remote attackers to cause a denial of service (child processing handler crash) via a request with the (1) s-maxage, (2) max-age, (3) min-fresh, or (4) max-stale Cache-Control headers without a value.. EPSS estimates a 11.79% chance of exploitation in the next 30 days.

Description

cache_util.c in the mod_cache module in Apache HTTP Server (httpd), when caching is enabled and a threaded Multi-Processing Module (MPM) is used, allows remote attackers to cause a denial of service (child processing handler crash) via a request with the (1) s-maxage, (2) max-age, (3) min-fresh, or (4) max-stale Cache-Control headers without a value.

Metrics

EPSS Probability
11.79%

95.6th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
AppleMac Os X Server10.0
AppleMac Os X Server10.1
AppleMac Os X Server10.1.1
AppleMac Os X Server10.1.2
AppleMac Os X Server10.1.3
AppleMac Os X Server10.1.4
AppleMac Os X Server10.1.5
AppleMac Os X Server10.2
AppleMac Os X Server10.2.1
AppleMac Os X Server10.2.2
AppleMac Os X Server10.2.3
AppleMac Os X Server10.2.4
AppleMac Os X Server10.2.5
AppleMac Os X Server10.2.6
AppleMac Os X Server10.2.7
AppleMac Os X Server10.2.8
AppleMac Os X Server10.3
AppleMac Os X Server10.3.1
AppleMac Os X Server10.3.2
AppleMac Os X Server10.3.3
AppleMac Os X Server10.3.4
AppleMac Os X Server10.3.5
AppleMac Os X Server10.3.6
AppleMac Os X Server10.3.7
AppleMac Os X Server10.3.8
AppleMac Os X Server10.3.9
AppleMac Os X Server10.4
AppleMac Os X Server10.4.1
AppleMac Os X Server10.4.2
AppleMac Os X Server10.4.3
AppleMac Os X Server10.4.4
AppleMac Os X Server10.4.5
AppleMac Os X Server10.4.6
AppleMac Os X Server10.4.7
AppleMac Os X Server10.4.8
AppleMac Os X Server10.4.9
ApacheHttp Server>= 2.0.37, < 2.0.61
ApacheHttp Server>= 2.2.0, < 2.2.6

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2007-1863?
cache_util.c in the mod_cache module in Apache HTTP Server (httpd), when caching is enabled and a threaded Multi-Processing Module (MPM) is used, allows remote attackers to cause a denial of service (child processing handler crash) via a request with the (1) s-maxage, (2) max-age, (3) min-fresh, or (4) max-stale Cache-Control headers without a value.
How severe is CVE-2007-1863?
Severity scoring for CVE-2007-1863 is pending analysis. The EPSS model estimates a 11.79% probability of exploitation in the next 30 days.
How do I fix CVE-2007-1863?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2007-1863?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST