CVE-2007-1862
Description
The recall_headers function in mod_mem_cache in Apache 2.2.4 does not properly copy all levels of header data, which can cause Apache to return HTTP headers containing previously used data, which could be used by remote attackers to obtain potentially sensitive information.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Apache 2.2.4 mod_mem_cache's recall_headers function fails to properly clear all header data, leaking previously used headers to remote attackers.
Vulnerability
In Apache HTTP Server 2.2.4, the recall_headers function in mod_mem_cache does not properly copy all levels of header data when serving cached responses. This flaw can cause the server to return HTTP headers containing previously used data from other requests, potentially exposing sensitive information. The vulnerability affects Apache 2.2.4 and possibly earlier versions in the 2.2.x branch [1][2].
Exploitation
A remote attacker can exploit this vulnerability by sending crafted requests to an Apache server that uses mod_mem_cache. The attacker does not need authentication; the issue is triggered when the server serves a cached response and fails to clear all header levels, thus returning stale headers from prior requests [1]. No user interaction is required.
Impact
Successful exploitation allows a remote attacker to obtain potentially sensitive information from HTTP headers that were previously used by the server for other clients. This could include session tokens, internal IP addresses, or other confidential data, leading to information disclosure [1][3].
Mitigation
Apache HTTP Server 2.2 reached End-of-Life in December 2017, and no official fix was released for this issue in the 2.2.x branch [1]. Users are strongly advised to upgrade to a supported version (2.4.x or later). As a workaround, disabling mod_mem_cache or avoiding the use of caching in sensitive environments may reduce exposure [3]. No patch is available from the Apache project for 2.2.x.
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- cpe:2.3:a:apache:http_server:2.2.4:*:*:*:*:*:*:*
- Range: =2.2.4
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
30- bugs.gentoo.org/show_bug.cginvd
- httpd.apache.org/security/vulnerabilities_22.htmlnvd
- issues.apache.org/bugzilla/show_bug.cginvd
- osvdb.org/38641nvd
- people.apache.org/~covener/2.2.x-mod_memcache-poolmgmt.diffnvd
- secunia.com/advisories/26273nvd
- secunia.com/advisories/26842nvd
- secunia.com/advisories/27563nvd
- security.gentoo.org/glsa/glsa-200711-06.xmlnvd
- www.mandriva.com/security/advisoriesnvd
- www.mandriva.com/security/advisoriesnvd
- www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.htmlnvd
- www.redhat.com/archives/fedora-package-announce/2007-September/msg00320.htmlnvd
- www.securityfocus.com/bid/24553nvd
- www.vupen.com/english/advisories/2007/2231nvd
- www.vupen.com/english/advisories/2007/2727nvd
- lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3Envd
- lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3Envd
- lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3Envd
- lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3Envd
- lists.apache.org/thread.html/r652fc951306cdeca5a276e2021a34878a76695a9f3cfb6490b4a6840%40%3Ccvs.httpd.apache.org%3Envd
- lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3Envd
- lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3Envd
- lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Envd
- lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3Envd
- lists.apache.org/thread.html/rafd145ba6cd0a4ced113a5823cdaff45aeb36eb09855b216401c66d6%40%3Ccvs.httpd.apache.org%3Envd
- lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3Envd
- lists.apache.org/thread.html/reb542d2038e9c331506e0cbff881b47e40fbe2bd93ff00979e60cdf7%40%3Ccvs.httpd.apache.org%3Envd
- lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Envd
- lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3Envd
News mentions
0No linked articles in our index yet.