← All CVEs

CVE-2011-3192

high · 7.8

The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited in the wild in August 2011, a different vulnerability than CVE-2007-0086.

7.8
CVSS
98.8%
EPSS (exploit prob.)
100th
EPSS percentile
2011-08-29
Published

AV:N/AC:L/Au:N/C:N/I:N/A:C

Weaknesses

CWE-400

Affected products

VendorProductAffected versions
apachehttp_server>= 2.0.35, < 2.0.65
apachehttp_server>= 2.2.0, < 2.2.20
opensuseopensuse11.3
opensuseopensuse11.4
suselinux_enterprise_server10
suselinux_enterprise_server10
suselinux_enterprise_server10
suselinux_enterprise_server11
suselinux_enterprise_server11
suselinux_enterprise_software_development_kit10
suselinux_enterprise_software_development_kit10
suselinux_enterprise_software_development_kit11
canonicalubuntu_linux8.04
canonicalubuntu_linux10.04
canonicalubuntu_linux10.10
canonicalubuntu_linux11.04

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2011-3192