httpd mod_cache segfault
Published Jun 27, 2007
5.0
MEDIUMCVSS 2.0
EPSS 11.79%
Description
cache_util.c in the mod_cache module in Apache HTTP Server (httpd), when caching is enabled and a threaded Multi-Processing Module (MPM) is used, allows remote attackers to cause a denial of service (child processing handler crash) via a request with the (1) s-maxage, (2) max-age, (3) min-fresh, or (4) max-stale Cache-Control headers without a value.
Affected products
No data.
Configuration 1
- 10.0
- 10.1
- 10.1.1
- 10.1.2
- 10.1.3
- 10.1.4
- 10.1.5
- 10.2
- 10.2.1
- 10.2.2
- 10.2.3
- 10.2.4
- 10.2.5
- 10.2.6
- 10.2.7
- 10.2.8
- 10.3
- 10.3.1
- 10.3.2
- 10.3.3
- 10.3.4
- 10.3.5
- 10.3.6
- 10.3.7
- 10.3.8
- 10.3.9
- 10.4
- 10.4.1
- 10.4.2
- 10.4.3
- 10.4.4
- 10.4.5
- 10.4.6
- 10.4.7
- 10.4.8
- 10.4.9
Configuration 2
- ≥ 2.0.37 · < 2.0.61
- ≥ 2.2.0 · < 2.2.6
No data.
Red Hat Certificate System 7.3
ant-0:1.6.5-1jpp_1rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
avalon-logkit-0:1.2-2jpp_4rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
axis-0:1.2.1-1jpp_3rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
classpathx-jaf-0:1.0-2jpp_6rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
classpathx-mail-0:1.1.1-2jpp_8rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
geronimo-specs-0:1.0-0.M4.1jpp_10rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
jakarta-commons-modeler-0:2.0-3jpp_2rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
log4j-0:1.2.12-1jpp_1rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
mx4j-1:3.0.1-1jpp_4rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
pcsc-lite-0:1.3.3-3.el4
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
rhpki-ca-0:7.3.0-20.el4
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
rhpki-java-tools-0:7.3.0-10.el4
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
rhpki-kra-0:7.3.0-14.el4
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
rhpki-manage-0:7.3.0-19.el4
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
rhpki-native-tools-0:7.3.0-6.el4
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
rhpki-ocsp-0:7.3.0-13.el4
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
rhpki-tks-0:7.3.0-13.el4
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
tomcat5-0:5.5.23-0jpp_4rh.16
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
xerces-j2-0:2.7.1-1jpp_1rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
xml-commons-0:1.3.02-2jpp_1rh
Fixed · RHSA-2010:0602
Red Hat Enterprise Linux 3
httpd-0:2.0.46-67.ent
Fixed · RHSA-2007:0533
Red Hat Enterprise Linux 4
httpd-0:2.0.52-32.2.ent
Fixed · RHSA-2007:0534
Red Hat Enterprise Linux 5
httpd-0:2.2.3-7.el5
Fixed · RHSA-2007:0556
Red Hat Web Application Stack for RHEL 4
httpd-0:2.0.59-1.el4s1.7
Fixed · RHSA-2007:0557
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Certificate System 7.3 | ant-0:1.6.5-1jpp_1rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | avalon-logkit-0:1.2-2jpp_4rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | axis-0:1.2.1-1jpp_3rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | classpathx-jaf-0:1.0-2jpp_6rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | classpathx-mail-0:1.1.1-2jpp_8rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | geronimo-specs-0:1.0-0.M4.1jpp_10rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | jakarta-commons-modeler-0:2.0-3jpp_2rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | log4j-0:1.2.12-1jpp_1rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | mx4j-1:3.0.1-1jpp_4rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | pcsc-lite-0:1.3.3-3.el4 | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | rhpki-ca-0:7.3.0-20.el4 | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | rhpki-java-tools-0:7.3.0-10.el4 | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | rhpki-kra-0:7.3.0-14.el4 | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | rhpki-manage-0:7.3.0-19.el4 | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | rhpki-native-tools-0:7.3.0-6.el4 | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | rhpki-ocsp-0:7.3.0-13.el4 | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | rhpki-tks-0:7.3.0-13.el4 | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | tomcat5-0:5.5.23-0jpp_4rh.16 | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | xerces-j2-0:2.7.1-1jpp_1rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | xml-commons-0:1.3.02-2jpp_1rh | Fixed | RHSA-2010:0602 |
| Red Hat Enterprise Linux 3 | httpd-0:2.0.46-67.ent | Fixed | RHSA-2007:0533 |
| Red Hat Enterprise Linux 4 | httpd-0:2.0.52-32.2.ent | Fixed | RHSA-2007:0534 |
| Red Hat Enterprise Linux 5 | httpd-0:2.2.3-7.el5 | Fixed | RHSA-2007:0556 |
| Red Hat Web Application Stack for RHEL 4 | httpd-0:2.0.59-1.el4s1.7 | Fixed | RHSA-2007:0557 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (32 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 11.79% (0.11786) | 95.96th | v5 (v2026.06.15) |
| Jun 15, 2026 | 11.79% (0.11786) | 95.53th | v5 (v2026.06.15) |
| Apr 7, 2026 | 27.99% (0.27987) | 96.45th | v4 (v2025.03.14) |
| Feb 13, 2026 | 36.21% (0.36211) | 96.99th | v4 (v2025.03.14) |
| Dec 28, 2025 | 32.30% (0.32302) | 96.67th | v4 (v2025.03.14) |
| Dec 27, 2025 | 29.96% (0.29957) | 96.51th | v4 (v2025.03.14) |
| Dec 1, 2025 | 32.30% (0.32302) | 96.68th | v4 (v2025.03.14) |
| Oct 28, 2025 | 34.51% (0.34512) | 96.79th | v4 (v2025.03.14) |
| Oct 27, 2025 | 29.69% (0.29687) | 96.42th | v4 (v2025.03.14) |
| Oct 1, 2025 | 34.51% (0.34512) | 96.88th | v4 (v2025.03.14) |
| Jul 30, 2025 | 29.69% (0.29687) | 96.44th | v4 (v2025.03.14) |
| Jul 22, 2025 | 34.51% (0.34512) | 96.81th | v4 (v2025.03.14) |
| Mar 30, 2025 | 30.39% (0.30391) | 96.30th | v4 (v2025.03.14) |
| Mar 29, 2025 | 43.04% (0.43036) | 96.25th | v4 (v2025.03.14) |
| Mar 21, 2025 | 30.39% (0.30391) | 96.32th | v4 (v2025.03.14) |
| Mar 17, 2025 | 36.55% (0.36551) | 96.77th | v4 (v2025.03.14) |
| Jan 6, 2025 | 88.13% (0.88128) | 98.93th | v3 (v2023.03.01) |
| Dec 17, 2024 | 89.41% (0.89412) | 99.00th | v3 (v2023.03.01) |
| Sep 30, 2024 | 85.68% (0.85682) | 98.60th | v3 (v2023.03.01) |
| Aug 22, 2024 | 83.27% (0.83265) | 98.50th | v3 (v2023.03.01) |
| Jul 15, 2024 | 85.06% (0.85063) | 98.56th | v3 (v2023.03.01) |
| Jun 7, 2024 | 82.61% (0.82611) | 98.42th | v3 (v2023.03.01) |
| Apr 30, 2024 | 87.71% (0.87712) | 98.62th | v3 (v2023.03.01) |
| Mar 23, 2024 | 87.68% (0.87682) | 98.57th | v3 (v2023.03.01) |
| Feb 16, 2024 | 93.36% (0.93355) | 99.00th | v3 (v2023.03.01) |
| Nov 29, 2023 | 95.39% (0.95395) | 99.18th | v3 (v2023.03.01) |
| Oct 22, 2023 | 95.64% (0.95637) | 99.20th | v3 (v2023.03.01) |
| Mar 7, 2023 | 95.70% (0.95696) | 98.99th | v3 (v2023.03.01) |
| Mar 6, 2023 | 5.55% (0.05552) | 90.03th | v2 (v2022.01.01) |
| Feb 13, 2023 | 5.55% (0.05552) | 89.69th | v2 (v2022.01.01) |
| Apr 1, 2022 | 9.12% (0.09121) | 93.62th | v2 (v2022.01.01) |
| Feb 4, 2022 | 9.12% (0.09121) | 86.89th | v2 (v2022.01.01) |
No CWE recorded.
References (69)
- http://bugs.gentoo.org/show_bug.cgi?id=186219 x_refsource_CONFIRMThird Party Advisory
- http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=244658 x_refsource_MISCIssue Tracking
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795 vendor-advisoryx_refsource_HPBroken Link
- http://httpd.apache.org/security/vulnerabilities_20.html x_refsource_CONFIRMVendor Advisory
- http://httpd.apache.org/security/vulnerabilities_22.html x_refsource_CONFIRMVendor Advisory
- http://lists.apple.com/archives/security-announce/2008//May/msg00001.html vendor-advisoryx_refsource_APPLEThird Party Advisory
- http://lists.vmware.com/pipermail/security-announce/2009/000062.html mailing-listx_refsource_MLISTThird Party AdvisoryVDB Entry
- http://osvdb.org/37079 vdb-entryx_refsource_OSVDBBroken Link
- http://rhn.redhat.com/errata/RHSA-2007-0534.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2007-0556.html vendor-advisoryx_refsource_REDHATThird Party AdvisoryVDB Entry
- http://secunia.com/advisories/25830 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/25873 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/25920 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/26273 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/26443 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/26508 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/26822 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/26842 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/26993 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/27037 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/27563 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/27732 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/28606 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/30430 third-party-advisoryx_refsource_SECUNIABroken Link
- http://security.gentoo.org/glsa/glsa-200711-06.xml vendor-advisoryx_refsource_GENTOOThird Party Advisory
- http://support.avaya.com/elmodocs2/security/ASA-2007-353.htm x_refsource_CONFIRMThird Party Advisory
- http://svn.apache.org/viewvc?view=rev&revision=535617 x_refsource_CONFIRMThird Party Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg1PK49355 vendor-advisoryx_refsource_AIXAPARThird Party Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg1PK52702 vendor-advisoryx_refsource_AIXAPARThird Party Advisory
- http://www.fujitsu.com/global/support/software/security/products-f/interstage-200802e.html x_refsource_CONFIRMThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:140 vendor-advisoryx_refsource_MANDRIVAThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:141 vendor-advisoryx_refsource_MANDRIVAThird Party Advisory
- http://www.novell.com/linux/security/advisories/2007_61_apache2.html vendor-advisoryx_refsource_SUSEBroken Link
- http://www.redhat.com/archives/fedora-package-announce/2007-September/msg00320.html vendor-advisoryx_refsource_FEDORAMailing ListThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0557.html vendor-advisoryx_refsource_REDHATBroken Link
- http://www.securityfocus.com/archive/1/505990/100/0/threaded mailing-listx_refsource_BUGTRAQThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/24649 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id?1018303 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- http://www.trustix.org/errata/2007/0026/ vendor-advisoryx_refsource_TRUSTIXBroken Link
- http://www.ubuntu.com/usn/usn-499-1 vendor-advisoryx_refsource_UBUNTUThird Party AdvisoryVDB Entry
- http://www.us-cert.gov/cas/techalerts/TA08-150A.html third-party-advisoryx_refsource_CERTBroken Link
- http://www.vupen.com/english/advisories/2007/2727 vdb-entryx_refsource_VUPENPermissions RequiredThird Party Advisory
- http://www.vupen.com/english/advisories/2007/3283 vdb-entryx_refsource_VUPENPermissions RequiredThird Party Advisory
- http://www.vupen.com/english/advisories/2007/3386 vdb-entryx_refsource_VUPENPermissions RequiredThird Party Advisory
- http://www.vupen.com/english/advisories/2008/0233 vdb-entryx_refsource_VUPENPermissions RequiredThird Party Advisory
- http://www.vupen.com/english/advisories/2008/1697 vdb-entryx_refsource_VUPENPermissions RequiredThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2007-1863 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=244658 Issue Tracking
- https://issues.rpath.com/browse/RPL-1500 x_refsource_CONFIRMBroken Link
- https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.apache.org/thread.html/r652fc951306cdeca5a276e2021a34878a76695a9f3cfb6490b4a6840%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLISTMailing List
- https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.apache.org/thread.html/r8c9983f1172a3415f915ddb7e14de632d2d0c326eb1285755a024165%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.apache.org/thread.html/rafd145ba6cd0a4ced113a5823cdaff45aeb36eb09855b216401c66d6%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.apache.org/thread.html/reb542d2038e9c331506e0cbff881b47e40fbe2bd93ff00979e60cdf7%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2007-1863
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9824 vdb-entrysignaturex_refsource_OVALBroken Link
- https://rhn.redhat.com/errata/RHSA-2007-0533.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2007-1863
Change history (0)
No recorded changes yet.