CVE-2007-0086

NameCVE-2007-0086
DescriptionThe Apache HTTP Server, when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same fragment. NOTE: the severity of this issue has been disputed by third parties, who state that the large window size required by the attack is not normally supported or configured by the server, or that a DDoS-style attack would accomplish the same goal
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
apache2 (PTS)buster2.4.38-3+deb10u8vulnerable (unimportant)
buster (security)2.4.38-3+deb10u10vulnerable (unimportant)
bullseye2.4.56-1~deb11u2vulnerable (unimportant)
bullseye (security)2.4.56-1~deb11u1vulnerable (unimportant)
bookworm2.4.57-2vulnerable (unimportant)
sid, trixie2.4.58-1vulnerable (unimportant)

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
apachesource(unstable)(unfixed)unimportant
apache2source(unstable)(unfixed)unimportant

Search for package or bug name: Reporting problems