CVE-2007-3847

Summary

CVECVE-2007-3847
StatePUBLIC
Assigner[email protected]
Source PriorityCVE Program / NVD first with legacy fallback
Published2007-08-23 22:17:00 UTC
Updated2023-02-13 02:18:00 UTC
DescriptionThe date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a denial of service (caching forward proxy process crash) via crafted date headers that trigger a buffer over-read.

Risk And Classification

Problem Types: CWE-125

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Application Apache Http Server All All All All
Application Apache Http Server 2.3.0 All All All
Application Apache Http Server 2.3.0 All All All
Operating System Canonical Ubuntu Linux 6.06 All All All
Operating System Canonical Ubuntu Linux 6.10 All All All
Operating System Canonical Ubuntu Linux 7.04 All All All
Operating System Canonical Ubuntu Linux 7.10 All All All
Operating System Fedoraproject Fedora 7 All All All
Operating System Fedoraproject Fedora Core 6 All All All

References

ReferenceSourceLinkTags
Pony Mail! MISC lists.apache.org
Webmail : Solution de messagerie professionnelle - OVHcloud- OVH VUPEN www.vupen.com
rhn.redhat.com | Red Hat Support REDHAT www.redhat.com
IBM Fix list for IBM WebSphere Application Server V6.1 - United States CONFIRM www-1.ibm.com
Pony Mail! MLIST lists.apache.org
Mandriva update for apache - Advisories - Secunia SECUNIA secunia.com
rhn.redhat.com | Red Hat Support REDHAT www.redhat.com
Avaya Products Apache mod_proxy "date" Denial of Service - Advisories - Secunia SECUNIA secunia.com
Pony Mail! MISC lists.apache.org
About Security Update 2008-002 CONFIRM docs.info.apple.com
Pony Mail! MLIST lists.apache.org
Pony Mail! MLIST lists.apache.org
Webmail : Solution de messagerie professionnelle - OVHcloud- OVH VUPEN www.vupen.com
Red Hat Customer Portal MISC access.redhat.com
HP-UX update for Apache - Advisories - Secunia SECUNIA secunia.com
Pony Mail! MLIST lists.apache.org
Oracle Critical Patch Update - July 2013 CONFIRM www.oracle.com
Pony Mail! MISC lists.apache.org
Fedora update for httpd - Advisories - Secunia SECUNIA secunia.com
Red Hat update for httpd - Secunia Advisories - Vulnerability Intelligence - Secunia.com SECUNIA secunia.com
Pony Mail! MISC lists.apache.org
Pony Mail! MISC lists.apache.org
Red Hat Customer Portal - Access to 24x7 support and knowledge MISC access.redhat.com
Pony Mail! MISC lists.apache.org
Fedora update for httpd - Advisories - Secunia SECUNIA secunia.com
Pony Mail! MISC lists.apache.org
Pony Mail! MISC lists.apache.org
Pony Mail! MLIST lists.apache.org
Security Announcement SUSE www.novell.com
Pony Mail! MISC lists.apache.org
Pony Mail! MISC lists.apache.org
[Security-announce] VMSA-2009-0010 VMware Hosted products update libpng and Apache HTTP Server MLIST lists.vmware.com
Pony Mail! MLIST lists.apache.org
Pony Mail! MLIST lists.apache.org
Pony Mail! MISC lists.apache.org
Webmail : Solution de messagerie professionnelle - OVHcloud- OVH VUPEN www.vupen.com
Pony Mail! MLIST lists.apache.org
Pony Mail! MLIST lists.apache.org
Pony Mail! MISC lists.apache.org
Red Hat Customer Portal MISC access.redhat.com
IBM PK50469: CVE-2007-3847 PROXY BUFFER OVER-READ VULNERABILITY - United States AIXAPAR www-1.ibm.com
access.redhat.com | CVE-2007-3847 MISC access.redhat.com
The Slackware Linux Project: Slackware Security Advisories SLACKWARE slackware.com
Pony Mail! MISC lists.apache.org
SecurityTracker.com Archives - Apache mod_proxy Bug Lets Remote Users Deny Service SECTRACK www.securitytracker.com
Pony Mail! MLIST lists.apache.org
Pony Mail! MISC lists.apache.org
Webmail : Solution de messagerie professionnelle - OVHcloud- OVH VUPEN www.vupen.com
[SECURITY] Fedora Core 6 Update: httpd-2.2.6-1.fc6 FEDORA www.redhat.com
Webmail- OVH VUPEN www.vupen.com
Red Hat Customer Portal MISC access.redhat.com
Pony Mail! MLIST lists.apache.org
issues.rpath.com/browse/RPL-1710 CONFIRM issues.rpath.com
250731 – (CVE-2007-3847) CVE-2007-3847 httpd: out of bounds read MISC bugzilla.redhat.com
IBM WebSphere Application Server for z/OS HTTP Server Vulnerabilities - Advisories - Secunia SECUNIA secunia.com
Pony Mail! MLIST lists.apache.org
Slackware update for apache - Advisories - Secunia SECUNIA secunia.com
USN-575-1: Apache vulnerabilities | Ubuntu UBUNTU www.ubuntu.com
Pony Mail! MISC lists.apache.org
Mac OS X Security Update Fixes Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com SECUNIA secunia.com
Webmail : Solution de messagerie professionnelle - OVHcloud- OVH VUPEN www.vupen.com
HPSBUX02273 HP h20000.www2.hp.com
IBM HTTP Server mod_proxy "date" Denial of Service Vulnerability - Advisories - Secunia SECUNIA secunia.com
US-CERT Technical Cyber Security Alert TA08-150A -- Apple Updates for Multiple Vulnerabilities CERT www.us-cert.gov US Government Resource
httpd 2.2 vulnerabilities - The Apache HTTP Server Project CONFIRM httpd.apache.org
SecurityFocus BUGTRAQ www.securityfocus.com
Gentoo Bug 186219 - www-servers/apache Multiple issues (CVE-2006-{5752}, CVE-2007-{1862,1863,3304,3847,4465}) CONFIRM bugs.gentoo.org
Pony Mail! MISC lists.apache.org
PK52702: Z/OS IBM HTTP SERVER FOR WEBSPHERE (POWERED BY APACHE) FIX PACK 6.1.0.13 AIXAPAR www-1.ibm.com
Pony Mail! MLIST lists.apache.org
Apache HTTP Server Mod_Proxy Denial of Service Vulnerability BID www.securityfocus.com
Repository / Oval Repository OVAL oval.cisecurity.org
Pony Mail! MISC lists.apache.org
rhn.redhat.com | Red Hat Support REDHAT www.redhat.com
Webmail : Solution de messagerie professionnelle - OVHcloud- OVH VUPEN www.vupen.com
Red Hat update for httpd - Advisories - Secunia SECUNIA secunia.com
rhn.redhat.com | Red Hat Support REDHAT www.redhat.com
'Re: svn commit: r561616 - in /httpd/httpd/trunk: CHANGES modules/proxy/proxy_util.c' - MARC MLIST marc.info
rPath update for httpd and mod_ssl - Advisories - Secunia SECUNIA secunia.com
Apple Mac OS X Security Update Fixes Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com SECUNIA secunia.com
Pony Mail! MLIST lists.apache.org
Apache mod_proxy "date" Denial of Service Vulnerability - Advisories - Secunia SECUNIA secunia.com
Pony Mail! MLIST lists.apache.org
Interstage HTTP Server Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com SECUNIA secunia.com
SUSE update for apache2 - Advisories - Secunia SECUNIA secunia.com
Webmail : Solution de messagerie professionnelle - OVHcloud- OVH VUPEN www.vupen.com
Pony Mail! MISC lists.apache.org
Red Hat Customer Portal MISC access.redhat.com
Pony Mail! MISC lists.apache.org
Advisories | Mandriva MANDRIVA www.mandriva.com
Pony Mail! MLIST lists.apache.org
Pony Mail! MISC lists.apache.org
Pony Mail! MLIST lists.apache.org
Pony Mail! MLIST lists.apache.org
'svn commit: r561616 - in /httpd/httpd/trunk: CHANGES' - MARC MLIST marc.info
Gentoo Linux Documentation -- Apache: Multiple vulnerabilities GENTOO security.gentoo.org
[apache-httpd-dev] 20070801 Re: svn commit: r561616 - in /httpd/httpd/trunk: CHANGES modules/proxy/proxy_util.c MLIST marc.info
APPLE-SA-2008-05-28 Security Update 2008-003 and Mac OS X v10.5.3 APPLE lists.apple.com
Ubuntu update for apache2 - Secunia Advisories - Vulnerability Information - Secunia.com SECUNIA secunia.com
Pony Mail! MLIST lists.apache.org
APPLE-SA-2008-03-18 Security Update 2008-002 APPLE lists.apple.com
Apache httpd 2.0 vulnerabilities - The Apache HTTP Server Project CONFIRM httpd.apache.org
Pony Mail! MISC lists.apache.org
This page provides Security Information. : FUJITSU CONFIRM www.fujitsu.com
ASA-2007-500 (RHSA-2007-0747) CONFIRM support.avaya.com
Pony Mail! MLIST lists.apache.org
Gentoo update for apache - Advisories - Secunia SECUNIA secunia.com
Pony Mail! MISC lists.apache.org
Pony Mail! MLIST lists.apache.org
Pony Mail! MLIST lists.apache.org
[SECURITY] Fedora 7 Update: httpd-2.2.6-1.fc7 FEDORA www.redhat.com
Pony Mail! MITRE lists.apache.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

Vendor Comments And Credit

OrganizationPublishedContributorStatement
Apache2008-07-02Mark J CoxFixed in Apache HTTP Server 2.2.6 and 2.0.61: http://httpd.apache.org/security/vulnerabilities_22.html http://httpd.apache.org/security/vulnerabilities_20.html
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report