imPC@ndo IT

Tracker / CVE-2011-3192

CVE-2011-3192

High 7.8

The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited in the wild in August 2011, a different vulnerability than CVE-2007-0086.

Affected products and versions

apache http_server · 2.0.35 → 2.0.65
apache http_server · 2.2.0 → 2.2.20
canonical ubuntu_linux
opensuse opensuse
suse linux_enterprise_server
suse linux_enterprise_software_development_kit

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References