VDB
CVE-2007-6258
CVE-2007-6258
PUBLISHED
CVSS 7.5 HIGH
Multiple stack-based buffer overflows in the legacy mod_jk2 2.0.3-DEV and earlier Apache module allow remote attackers to execute arbitrary code via a long (1) Host header, or (2) Hostname within a Host header.
EPSS 40.80% · 97.5th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
40.80%
97.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| apache | mod_jk | 2.0, 2.0.1, 2.0.2 |
| n/a | n/a | n/a |
| f5 | big-ip | 9.2.3.30 |
Timeline
- Feb 12, 2008 CVE Published
- Feb 12, 2008 PoC Published
- Apr 6, 2008 PoC Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- 20080212 IOActive Security Advisory: Legacy mod_jk2 Buffer Overflow mailing-list
- ADV-2008-0572 vdb
- 27752 vdb
- http://www.ioactive.com/pdfs/mod_jk2.pdf url
- 5330 exploit
- 3661 third-party-advisory
- VU#771937 third-party-advisory
- http://www.ioactive.com/vulnerabilities/mod_jk2LegacyBufferOverflowAdvisory.pdf url
- 5386 exploit
- https://nvd.nist.gov/vuln/detail/CVE-2007-6258 advisory