cbcvebase.
CVE-2011-0419
published 2011-05-16

CVE-2011-0419: Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP…

medium4.3CVSS 3.1
AVNACMAuNCNINAP
EXPLOIT
Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac OS X 10.6, Oracle Solaris 10, and Android, allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via *? sequences in the first argument, as demonstrated by attacks against mod_autoindex in httpd.

Affected

17 ranges
VendorProductVersion rangeFixed in
apacheapr-util
apacheapr-util
apachehttp_server
apachehttp_server2.0.0 – 2.0.65
apachehttp_server2.2.0 – 2.2.18
apachehttpd
apacheportable_runtime< 1.4.31.4.3
applemac_os_x
debianapr< apr 1.4.4-1 (bookworm)apr 1.4.4-1 (bookworm)
debianapr< apr 1.4.5-1 (bookworm)apr 1.4.5-1 (bookworm)
debiandebian_linux
debiandebian_linux
debiandebian_linux
netbsdnetbsd
openbsdopenbsd
oraclesolaris
suselinux_enterprise_server

CVSS provenance

nvd4.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM