CVE-2011-3607

Description

Integer overflow in the ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, allows local users to gain privileges via a .htaccess file with a crafted SetEnvIf directive, in conjunction with a crafted HTTP request header, leading to a heap-based buffer overflow.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.242

Associated Vulnerability

VulnerabilityOS Platform
Update Apache to version 2.2.21Windows
Update Apache to version 2.0.65Windows
Multiple vulnerabilities are fixed in Apache 2.2.2Windows
Multiple vulnerabilities are fixed in Apache 2.0.65Windows
Vulnerabilities CVE-2011-3607 are affected in Oracle HTTP Server 4.4Windows
Multiple vulnerabilities are fixed in OS X Lion Update 10.7.5 (Client)Mac
Multiple vulnerabilities are fixed in OS X Lion Update 10.7.5 (Client Combo)Mac
apache2 regression update(DSA-3325-2) apache2_2.2.22-13+deb7u6_i386.debLinux
Update Apache to version 2.2.21 (For Linux)Linux
Update Apache to version 2.0.65 (For Linux)Linux
CVE-2011-3607NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-600003OS X Lion Update 10.7.5 (Client)
PATCH-600004OS X Lion Update 10.7.5 (Client Combo)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234