Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-3348

Опубликовано: 14 сент. 2011
Источник: redhat
CVSS2: 5

Описание

The mod_proxy_ajp module in the Apache HTTP Server before 2.2.21, when used with mod_proxy_balancer in certain configurations, allows remote attackers to cause a denial of service (temporary "error state" in the backend server) via a malformed HTTP request.

Отчет

This issue did not affect the versions of httpd as shipped with Red Hat Enterprise Linux 4 and 5 as this flaw was introduced in version 2.2.12.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4httpdNot affected
Red Hat Enterprise Linux 5httpdNot affected
Red Hat Enterprise Linux 6httpdFixedRHSA-2011:139120.10.2011
Red Hat JBoss Enterprise Web Server 1 for RHEL 5httpdFixedRHSA-2012:054207.05.2012
Red Hat JBoss Enterprise Web Server 1 for RHEL 6httpdFixedRHSA-2012:054207.05.2012
Red Hat JBoss Web Server 1.0FixedRHSA-2012:054307.05.2012

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=736690httpd: mod_proxy_ajp remote temporary DoS

5 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 14 лет назад

The mod_proxy_ajp module in the Apache HTTP Server before 2.2.21, when used with mod_proxy_balancer in certain configurations, allows remote attackers to cause a denial of service (temporary "error state" in the backend server) via a malformed HTTP request.

nvd
почти 14 лет назад

The mod_proxy_ajp module in the Apache HTTP Server before 2.2.21, when used with mod_proxy_balancer in certain configurations, allows remote attackers to cause a denial of service (temporary "error state" in the backend server) via a malformed HTTP request.

debian
почти 14 лет назад

The mod_proxy_ajp module in the Apache HTTP Server before 2.2.21, when ...

github
больше 3 лет назад

The mod_proxy_ajp module in the Apache HTTP Server before 2.2.21, when used with mod_proxy_balancer in certain configurations, allows remote attackers to cause a denial of service (temporary "error state" in the backend server) via a malformed HTTP request.

oracle-oval
почти 14 лет назад

ELSA-2011-1391: httpd security and bug fix update (MODERATE)

5 Medium

CVSS2