Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-3192

Опубликовано: 20 авг. 2011
Источник: redhat
CVSS2: 5
EPSS Критический

Описание

The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited in the wild in August 2011, a different vulnerability than CVE-2007-0086.

Отчет

Before updated packages are deployed, users can deploy configuration changes to mitigate this flaw: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-3192#c18

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Directory Server 8httpdAffected
JBEWS 1.0 for RHEL 4httpd22FixedRHSA-2011:132921.09.2011
Red Hat Enterprise Linux 3 Extended Lifecycle SupporthttpdFixedRHSA-2011:130015.09.2011
Red Hat Enterprise Linux 4httpdFixedRHSA-2011:124531.08.2011
Red Hat Enterprise Linux 5httpdFixedRHSA-2011:124531.08.2011
Red Hat Enterprise Linux 5httpdFixedRHSA-2011:129414.09.2011
Red Hat Enterprise Linux 5.3 Long LifehttpdFixedRHSA-2011:129414.09.2011
Red Hat Enterprise Linux 6httpdFixedRHSA-2011:124531.08.2011
Red Hat Enterprise Linux 6.0 EUS - Server OnlyhttpdFixedRHSA-2011:129414.09.2011
Red Hat JBoss Enterprise Web Server 1 for RHEL 5httpdFixedRHSA-2011:132921.09.2011

Показывать по

Дополнительная информация

Статус:

Important

EPSS

Процентиль: 100%
0.90456
Критический

5 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 14 лет назад

The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited in the wild in August 2011, a different vulnerability than CVE-2007-0086.

nvd
больше 14 лет назад

The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited in the wild in August 2011, a different vulnerability than CVE-2007-0086.

debian
больше 14 лет назад

The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2. ...

github
почти 4 года назад

The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited in the wild in August 2011, a different vulnerability than CVE-2007-0086.

oracle-oval
больше 14 лет назад

ELSA-2011-1245: httpd security update (IMPORTANT)

EPSS

Процентиль: 100%
0.90456
Критический

5 Medium

CVSS2