cbcvebase.
CVE-2006-3747
published 2006-07-28

CVE-2006-3747: Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2…

high7.6CVSS 3.1
AVNACHAuNCCICAC
EXPLOIT
Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2, when RewriteEngine is enabled, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted URLs that are not properly handled using certain rewrite rules.

Affected

9 ranges
VendorProductVersion rangeFixed in
apachehttp_server>= 1.3.28 < 1.3.371.3.37
apachehttp_server>= 2.0.46 < 2.0.592.0.59
apachehttp_server>= 2.2.0 < 2.2.32.2.3
apachehttpd
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianapache2< apache2 2.0.55-4.1 (bookworm)apache2 2.0.55-4.1 (bookworm)
debiandebian_linux

CVSS provenance

nvd7.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
ghsa5.0MEDIUM
osv7.6HIGH