CVE-2011-3192
high · 7.8The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited in the wild in August 2011, a different vulnerability than CVE-2007-0086.
7.8
CVSS
98.8%
EPSS (exploit prob.)
100th
EPSS percentile
2011-08-29
Published
AV:N/AC:L/Au:N/C:N/I:N/A:C
Weaknesses
CWE-400
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apache | http_server | >= 2.0.35, < 2.0.65 |
| apache | http_server | >= 2.2.0, < 2.2.20 |
| opensuse | opensuse | 11.3 |
| opensuse | opensuse | 11.4 |
| suse | linux_enterprise_server | 10 |
| suse | linux_enterprise_server | 10 |
| suse | linux_enterprise_server | 10 |
| suse | linux_enterprise_server | 11 |
| suse | linux_enterprise_server | 11 |
| suse | linux_enterprise_software_development_kit | 10 |
| suse | linux_enterprise_software_development_kit | 10 |
| suse | linux_enterprise_software_development_kit | 11 |
| canonical | ubuntu_linux | 8.04 |
| canonical | ubuntu_linux | 10.04 |
| canonical | ubuntu_linux | 10.10 |
| canonical | ubuntu_linux | 11.04 |
Check a specific version with /api/v1/cve/match.
References
- http://archives.neohapsis.com/archives/fulldisclosure/2011-08/0285.html
- http://blogs.oracle.com/security/entry/security_alert_for_cve_2011
- http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html
- http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00006.html
- http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00009.html
- http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00011.html
- http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00008.html
- http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00011.html
- http://mail-archives.apache.org/mod_mbox/httpd-announce/201108.mbox/%3c20110824161640.122D387DD%40minotaur.apache.org%3e
- http://mail-archives.apache.org/mod_mbox/httpd-dev/201108.mbox/%3cCAAPSnn2PO-d-C4nQt_TES2RRWiZr7urefhTKPWBC1b+K1Dqc7g%40mail.gmail.com%3e
- http://marc.info/?l=bugtraq&m=131551295528105&w=2
- http://marc.info/?l=bugtraq&m=131731002122529&w=2
- http://marc.info/?l=bugtraq&m=132033751509019&w=2
- http://marc.info/?l=bugtraq&m=133477473521382&w=2
- http://marc.info/?l=bugtraq&m=133951357207000&w=2
- http://marc.info/?l=bugtraq&m=134987041210674&w=2
- http://osvdb.org/74721
- http://seclists.org/fulldisclosure/2011/Aug/175
- http://secunia.com/advisories/45606
- http://secunia.com/advisories/45937
- http://secunia.com/advisories/46000
- http://secunia.com/advisories/46125
- http://secunia.com/advisories/46126
- http://securitytracker.com/id?1025960
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2011-3192