CVE-2011-3192

Description

The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited in the wild in August 2011, a different vulnerability than CVE-2007-0086.

Risk Information

Base Score
9.1
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
EPSS Score
Exploitation Probability
90.456

Associated Vulnerability

VulnerabilityOS Platform
Update Apache to version 2.2.19Windows
Update Apache to version 2.0.65Windows
Multiple vulnerabilities are fixed in Apache 2.0.65Windows
Vulnerabilities CVE-2014-8730,CVE-2011-3192,CVE-2015-1829,CVE-2015-0138 are fixed in IBM HTTP 6.0.2.43Windows
Multiple vulnerabilities are affected in Oracle HTTP Server 5.0Windows
Update Apache to version 2.2.19 (For Linux)Linux
Update Apache to version 2.0.65 (For Linux)Linux
Uncontrolled Resource Consumption Vulnerability (CVE-2011-3192)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234