{"id":"ECHO-1e54-75fe-1aae","summary":"Local DoS in Apache httpd 2.0.59/2.2.4 with the Prefork MPM: a worker\nprocess can stop request processing or force the master to fork many\nworkers. Both the Apache and Red Hat vendors state this is \"by design\"\nand \"Not a vulnerability\" - in the httpd security model the less\nprivileged children fully handle connections, so any local user able to\nrun arbitrary code in a child can do this; hosts with untrusted local\nusers must use suexec. NVD lists only 2.0.59/2.2.4 (shipped is 2.4.68).\nDebian: unimportant.\nhttps://security-tracker.debian.org/tracker/CVE-2007-3303\n","modified":"2026-07-13T16:30:03.935098197Z","published":"2026-05-28T15:41:03.698Z","withdrawn":"2026-07-13T15:45:01.813Z","upstream":["CVE-2007-3303"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2007-3303"}],"affected":[{"package":{"name":"apache2","ecosystem":"Echo","purl":"pkg:deb/echo/apache2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.68-1~deb13u1"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-1e54-75fe-1aae.json"}}],"schema_version":"1.9.0"}