CVE-2011-0419
Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac OS…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 30.4%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac OS X 10.6, Oracle Solaris 10, and Android, allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via *? sequences in the first argument, as demonstrated by attacks against mod_autoindex in httpd.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
- EPSS
- 30.41% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-770
- Affected
- apache/portable runtime · apache/http server · apple/mac os x · freebsd/freebsd · google/android · netbsd/netbsd · openbsd/openbsd · oracle/solaris · debian/debian linux · suse/linux enterprise server
- Source
- cret@cert.org
References
- http://cvsweb.netbsd.org/bsdweb.cgi/src/lib/libc/gen/fnmatch.c#rev1.22Third Party Advisory
- http://cxib.net/stuff/apache.fnmatch.phpsPatch, Third Party Advisory
- http://cxib.net/stuff/apr_fnmatch.txtsThird Party Advisory
- http://httpd.apache.org/security/vulnerabilities_22.htmlVendor Advisory
- http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00011.htmlMailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=131551295528105&w=2Issue Tracking, Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=131731002122529&w=2Issue Tracking, Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=132033751509019&w=2Issue Tracking, Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=134987041210674&w=2Issue Tracking, Mailing List, Third Party Advisory
- http://secunia.com/advisories/44490Not Applicable, Vendor Advisory
- http://secunia.com/advisories/44564Not Applicable, Vendor Advisory
- http://secunia.com/advisories/44574Not Applicable, Vendor Advisory
- http://secunia.com/advisories/48308Not Applicable
- http://securityreason.com/achievement_securityalert/98Exploit, Third Party Advisory
- http://securityreason.com/securityalert/8246Exploit, Third Party Advisory
- http://securitytracker.com/id?1025527Broken Link, Third Party Advisory, VDB Entry
- http://support.apple.com/kb/HT5002Third Party Advisory
- http://svn.apache.org/viewvc/apr/apr/branches/1.4.x/strings/apr_fnmatch.c?r1=731029&r2=1098902Patch, Vendor Advisory
- http://svn.apache.org/viewvc?view=revision&revision=1098188Patch, Vendor Advisory
- http://svn.apache.org/viewvc?view=revision&revision=1098799Patch, Vendor Advisory
- http://www.apache.org/dist/apr/Announcement1.x.htmlPatch, Vendor Advisory
- http://www.apache.org/dist/apr/CHANGES-APR-1.4Broken Link
- http://www.apache.org/dist/httpd/Announcement2.2.htmlPatch, Vendor Advisory
- http://www.debian.org/security/2011/dsa-2237Third Party Advisory
- http://www.mail-archive.com/dev%40apr.apache.org/msg23960.htmlMailing List, Third Party Advisory
- http://www.mail-archive.com/dev%40apr.apache.org/msg23961.htmlMailing List, Third Party Advisory
- http://www.mail-archive.com/dev%40apr.apache.org/msg23976.htmlMailing List, Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:084Broken Link
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:150Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.