CVE-2011-3192
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 98.8%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited in the wild in August 2011, a different vulnerability than CVE-2007-0086.
- CVSS 2.0
- 7.8 HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
- EPSS
- 98.83% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-400
- Affected
- apache/http server · opensuse/opensuse · suse/linux enterprise server · suse/linux enterprise software development kit · canonical/ubuntu linux
- Source
- secalert@redhat.com
References
- http://archives.neohapsis.com/archives/fulldisclosure/2011-08/0285.htmlBroken Link
- http://blogs.oracle.com/security/entry/security_alert_for_cve_2011Broken Link
- http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00006.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00009.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00010.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00011.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00008.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00011.htmlMailing List, Third Party Advisory
- http://mail-archives.apache.org/mod_mbox/httpd-announce/201108.mbox/%3c20110824161640.122D387DD%40minotaur.apache.org%3e
- http://mail-archives.apache.org/mod_mbox/httpd-dev/201108.mbox/%3cCAAPSnn2PO-d-C4nQt_TES2RRWiZr7urefhTKPWBC1b+K1Dqc7g%40mail.gmail.com%3e
- http://marc.info/?l=bugtraq&m=131551295528105&w=2Issue Tracking, Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=131731002122529&w=2Issue Tracking, Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=132033751509019&w=2Issue Tracking, Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=133477473521382&w=2Issue Tracking, Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=133951357207000&w=2Issue Tracking, Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=134987041210674&w=2Issue Tracking, Mailing List
- http://osvdb.org/74721Broken Link
- http://seclists.org/fulldisclosure/2011/Aug/175Exploit, Mailing List, Third Party Advisory
- http://secunia.com/advisories/45606Not Applicable, Vendor Advisory
- http://secunia.com/advisories/45937Not Applicable
- http://secunia.com/advisories/46000Not Applicable
- http://secunia.com/advisories/46125Not Applicable
- http://secunia.com/advisories/46126Not Applicable
- http://securitytracker.com/id?1025960Broken Link, Third Party Advisory, VDB Entry
- http://support.apple.com/kb/HT5002Third Party Advisory
- http://www.apache.org/dist/httpd/Announcement2.2.htmlBroken Link
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080b90d73.shtmlThird Party Advisory
- http://www.exploit-db.com/exploits/17696Exploit, Third Party Advisory, VDB Entry
- http://www.gossamer-threads.com/lists/apache/dev/401638Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.