← All CVEs

CVE-2011-0419

medium · 4.3

Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac OS X 10.6, Oracle Solaris 10, and Android, allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via *? sequences in the first argument, as demonstrated by attacks against mod_autoindex in httpd.

4.3
CVSS
30.4%
EPSS (exploit prob.)
98th
EPSS percentile
2011-05-16
Published

AV:N/AC:M/Au:N/C:N/I:N/A:P

Weaknesses

CWE-770

Affected products

VendorProductAffected versions
apacheportable_runtime< 1.4.3
apachehttp_server>= 2.0.0, <= 2.0.65
apachehttp_server>= 2.2.0, <= 2.2.18
applemac_os_x10.6.0
freebsdfreebsdall versions
googleandroidall versions
netbsdnetbsd5.1
openbsdopenbsd4.8
oraclesolaris10
debiandebian_linux5.0
debiandebian_linux6.0
debiandebian_linux7.0
suselinux_enterprise_server10

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2011-0419