http://svn.apache.org/viewvc?view=rev&revision=535617 * Prevent a segmentation fault if one of the Cache-Control headers s-maxage, max-age, min-fresh, max-stale has no value assigned. In this case ignore s-maxage, max-age, min-fresh. For max-stale it is valid to set no value. In this case set max-stale to 1 year to signal that the client is accepting a stale response of any age. This could be a DoS if a threaded MPM and mod_cache is used.
http://people.apache.org/~mjc/cve-2007-1863-2.0.patch http://people.apache.org/~mjc/cve-2007-1863-2.2.patch
This issue was addressed in: Red Hat Application Stack: http://rhn.redhat.com/errata/RHSA-2007-0557.html Red Hat Enterprise Linux: http://rhn.redhat.com/errata/RHSA-2007-0534.html http://rhn.redhat.com/errata/RHSA-2007-0556.html http://rhn.redhat.com/errata/RHSA-2007-0533.html Fedora: https://admin.fedoraproject.org/updates/F7/FEDORA-2007-0704
This issue has been addressed in following products: Red Hat Certificate System 7.3 Via RHSA-2010:0602 https://rhn.redhat.com/errata/RHSA-2010-0602.html