ECHO-1e54-75fe-1aae

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-1e54-75fe-1aae.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-1e54-75fe-1aae
Upstream
Withdrawn
2026-07-13T15:45:01Z
Published
2026-05-28T15:41:03Z
Modified
2026-07-13T16:30:03Z
Summary
Local DoS in Apache httpd 2.0.59/2.2.4 with the Prefork MPM: a worker process can stop request processing or force the master to fork many workers. Both the Apache and Red Hat vendors state this is "by design" and "Not a vulnerability" - in the httpd security model the less privileged children fully handle connections, so any local user able to run arbitrary code in a child can do this; hosts with untrusted local users must use suexec. NVD lists only 2.0.59/2.2.4 (shipped is 2.4.68). Debian: unimportant. https://security-tracker.debian.org/tracker/CVE-2007-3303
Details
References

Affected packages

Echo / apache2

Package

Name
apache2
Purl
pkg:deb/echo/apache2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.4.68-1~deb13u1

Database specific

source
"https://advisory.echohq.com/osv/ECHO-1e54-75fe-1aae.json"