Lucene search

K
cve[email protected]CVE-2007-3304
HistoryJun 20, 2007 - 10:30 p.m.

CVE-2007-3304

2007-06-2022:30:00
web.nvd.nist.gov
78
2
apache
httpd
prefork mpm
denial of service
cve-2007-3304
sigusr1 killer

4.7 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:N/I:N/A:C

6.2 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.4%

Apache httpd 1.3.37, 2.0.59, and 2.2.4 with the Prefork MPM module, allows local users to cause a denial of service by modifying the worker_score and process_score arrays to reference an arbitrary process ID, which is sent a SIGUSR1 signal from the master process, aka β€œSIGUSR1 killer.”

Affected configurations

NVD
Node
apachehttp_serverRange1.3.0–1.3.39
OR
apachehttp_serverRange2.0.0–2.0.61
OR
apachehttp_serverRange2.2.0–2.2.6
Node
fedoraprojectfedoraMatch7
Node
redhatenterprise_linux_desktopMatch5.0
OR
redhatenterprise_linux_serverMatch5.0
OR
redhatenterprise_linux_workstationMatch5.0
Node
canonicalubuntu_linuxMatch6.06
OR
canonicalubuntu_linuxMatch6.10
OR
canonicalubuntu_linuxMatch7.04

References

Social References

More

4.7 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:N/I:N/A:C

6.2 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.4%