CVE-2011-0419

Description

Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac OS X 10.6, Oracle Solaris 10, and Android, allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via * sequences in the first argument, as demonstrated by attacks against mod_autoindex in httpd.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
55.527

Associated Vulnerability

VulnerabilityOS Platform
Update Apache to version 2.2.17Windows
Multiple vulnerabilities are fixed in Apache 2.0.65Windows
Multiple vulnerabilities are affected in Oracle HTTP Server 4.3Windows
Update Apache to version 2.2.17 (For Linux)Linux
Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2011-0419)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234