Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-3607

Опубликовано: 02 нояб. 2011
Источник: redhat
CVSS2: 4.4
EPSS Низкий

Описание

Integer overflow in the ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, allows local users to gain privileges via a .htaccess file with a crafted SetEnvIf directive, in conjunction with a crafted HTTP request header, leading to a heap-based buffer overflow.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Certificate System 7.3httpdWill not fix
Red Hat Directory Server 8httpdWill not fix
Red Hat Enterprise Linux 4httpdWill not fix
Red Hat Enterprise Linux 5httpdFixedRHSA-2012:032321.02.2012
Red Hat Enterprise Linux 6httpdFixedRHSA-2012:012813.02.2012
Red Hat JBoss Enterprise Web Server 1 for RHEL 5httpdFixedRHSA-2012:054207.05.2012
Red Hat JBoss Enterprise Web Server 1 for RHEL 6httpdFixedRHSA-2012:054207.05.2012
Red Hat JBoss Web Server 1.0FixedRHSA-2012:054307.05.2012

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=769844httpd: ap_pregsub Integer overflow to buffer overflow

EPSS

Процентиль: 60%
0.00404
Низкий

4.4 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 14 лет назад

Integer overflow in the ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, allows local users to gain privileges via a .htaccess file with a crafted SetEnvIf directive, in conjunction with a crafted HTTP request header, leading to a heap-based buffer overflow.

nvd
почти 14 лет назад

Integer overflow in the ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, allows local users to gain privileges via a .htaccess file with a crafted SetEnvIf directive, in conjunction with a crafted HTTP request header, leading to a heap-based buffer overflow.

debian
почти 14 лет назад

Integer overflow in the ap_pregsub function in server/util.c in the Ap ...

github
больше 3 лет назад

Integer overflow in the ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, allows local users to gain privileges via a .htaccess file with a crafted SetEnvIf directive, in conjunction with a crafted HTTP request header, leading to a heap-based buffer overflow.

oracle-oval
больше 13 лет назад

ELSA-2012-0323: httpd security update (MODERATE)

EPSS

Процентиль: 60%
0.00404
Низкий

4.4 Medium

CVSS2