CVE-2011-3192
PUBLISHEDThe byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of...
Recommended Action
Track for updates. Assess relevance to your asset inventory and enrichment workflows.
At a Glance
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited in the wild in August 2011, a different vulnerability than CVE-2007-0086.
- CVE Published
- Aug 29, 2011
- —
- —
- CVSS
- 7.8 High
- EPSS
- —
Affected Versions
| Vendor | Product | Version | Status |
|---|---|---|---|
| n/a |
n/a
|
n/a |
Affected |
CVE References
- RHSA-2011:1369 redhat.com · Vendor Advisory http://www.redhat.com/support/errata/RHSA-2011-1369.html
- RHSA-2011:1329 redhat.com · Vendor Advisory http://www.redhat.com/support/errata/RHSA-2011-1329.html
- HPSBUX02707 marc.info · Vendor Advisory http://marc.info/?l=bugtraq&m=131731002122529&w=2
- SUSE-SU-2011:1010 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00011...
- SSRT100966 marc.info · Vendor Advisory http://marc.info/?l=bugtraq&m=134987041210674&w=2
Show 67 more references
- openSUSE-SU-2011:0993 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00006...
- SSRT100624 marc.info · Vendor Advisory http://marc.info/?l=bugtraq&m=133477473521382&w=2
- HPSBUX02702 marc.info · Vendor Advisory http://marc.info/?l=bugtraq&m=131551295528105&w=2
- SSRT100619 marc.info · Vendor Advisory http://marc.info/?l=bugtraq&m=132033751509019&w=2
- 20110830 Apache HTTPd Range Header Denial of Service Vulnerability cisco.com · Vendor Advisory http://www.cisco.com/en/US/products/products_security_advisory09186a0...
- USN-1199-1 ubuntu.com · Vendor Advisory http://www.ubuntu.com/usn/USN-1199-1
- MDVSA-2011:130 mandriva.com · Vendor Advisory http://www.mandriva.com/security/advisories?name=MDVSA-2011:130
- APPLE-SA-2011-10-12-3 lists.apple.com · Vendor Advisory http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003....
- RHSA-2011:1330 redhat.com · Vendor Advisory http://www.redhat.com/support/errata/RHSA-2011-1330.html
- RHSA-2011:1245 redhat.com · Vendor Advisory http://www.redhat.com/support/errata/RHSA-2011-1245.html
- SSRT100852 marc.info · Vendor Advisory http://marc.info/?l=bugtraq&m=133951357207000&w=2
- SUSE-SU-2011:1216 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00008...
- SUSE-SU-2011:1007 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00010...
- SUSE-SU-2011:1000 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00009...
- RHSA-2011:1294 redhat.com · Vendor Advisory http://www.redhat.com/support/errata/RHSA-2011-1294.html
- MDVSA-2013:150 mandriva.com · Vendor Advisory http://www.mandriva.com/security/advisories?name=MDVSA-2013:150
- SUSE-SU-2011:1229 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00011...
- RHSA-2011:1300 redhat.com · Vendor Advisory http://www.redhat.com/support/errata/RHSA-2011-1300.html
- 45606 secunia.com · Third-Party Advisory http://secunia.com/advisories/45606
- 46000 secunia.com · Third-Party Advisory http://secunia.com/advisories/46000
- 46126 secunia.com · Third-Party Advisory http://secunia.com/advisories/46126
- 46125 secunia.com · Third-Party Advisory http://secunia.com/advisories/46125
- VU#405811 kb.cert.org · Third-Party Advisory http://www.kb.cert.org/vuls/id/405811
- 45937 secunia.com · Third-Party Advisory http://secunia.com/advisories/45937
- 17696 exploit-db.com · Exploit http://www.exploit-db.com/exploits/17696
- 1025960 securitytracker.com · VDB Entry http://securitytracker.com/id?1025960
- 49303 securityfocus.com · VDB Entry http://www.securityfocus.com/bid/49303
- 74721 osvdb.org · VDB Entry http://osvdb.org/74721
- oval:org.mitre.oval:def:14824 oval.cisecurity.org · VDB Entry https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.m...
- apache-http-byterange-dos(69396) exchange.xforce.ibmcloud.com · VDB Entry https://exchange.xforce.ibmcloud.com/vulnerabilities/69396
- oval:org.mitre.oval:def:18827 oval.cisecurity.org · VDB Entry https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.m...
- oval:org.mitre.oval:def:14762 oval.cisecurity.org · VDB Entry https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.m...
- [dev] 20110823 Re: DoS with mod_deflate & range requests mail-archives.apache.org · Mailing List http://mail-archives.apache.org/mod_mbox/httpd-dev/201108.mbox/%3cCAA...
- 20110824 Re: Apache Killer archives.neohapsis.com · Mailing List http://archives.neohapsis.com/archives/fulldisclosure/2011-08/0285.html
- [announce] 20110824 Advisory: Range header DoS vulnerability Apache HTTPD 1.3/2.x \(CVE-2011-3192\) mail-archives.apache.org · Mailing List http://mail-archives.apache.org/mod_mbox/httpd-announce/201108.mbox/%...
- 20110820 Apache Killer seclists.org · Mailing List http://seclists.org/fulldisclosure/2011/Aug/175
- [httpd-cvs] 20190815 svn commit: r1048742 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html lists.apache.org · Mailing List https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6be...
- [httpd-cvs] 20190815 svn commit: r1048743 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html lists.apache.org · Mailing List https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b03...
- [httpd-cvs] 20190815 svn commit: r1048743 [3/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html lists.apache.org · Mailing List https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7ce...
- [httpd-cvs] 20190815 svn commit: r1048742 [3/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html lists.apache.org · Mailing List https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d...
- [httpd-cvs] 20200401 svn commit: r1058586 [3/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html lists.apache.org · Mailing List https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d527...
- [httpd-cvs] 20200401 svn commit: r1058586 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html lists.apache.org · Mailing List https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac...
- [httpd-cvs] 20200401 svn commit: r1058587 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html lists.apache.org · Mailing List https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac78...
- [httpd-cvs] 20200401 svn commit: r1058587 [3/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html lists.apache.org · Mailing List https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f1563...
- [httpd-cvs] 20210330 svn commit: r1073139 [1/13] - in /websites/staging/httpd/trunk/content: ./ security/json/ lists.apache.org · Mailing List https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66...
- [httpd-cvs] 20210330 svn commit: r1073140 [3/4] - in /websites/staging/httpd/trunk/content: ./ security/cvejsontohtml.py security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html lists.apache.org · Mailing List https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81...
- [httpd-cvs] 20210330 svn commit: r1888194 [7/13] - /httpd/site/trunk/content/security/json/ lists.apache.org · Mailing List https://lists.apache.org/thread.html/r688df6f16f141e966a0a47f817e5593...
- [httpd-cvs] 20210330 svn commit: r1073140 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/cvejsontohtml.py security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html lists.apache.org · Mailing List https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a2...
- [httpd-cvs] 20210330 svn commit: r1073143 [2/3] - in /websites/staging/httpd/trunk/content: ./ security/ lists.apache.org · Mailing List https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f...
- [httpd-cvs] 20210330 svn commit: r1073139 [7/13] - in /websites/staging/httpd/trunk/content: ./ security/json/ lists.apache.org · Mailing List https://lists.apache.org/thread.html/re2e23465bbdb17ffe109d21b4f192e6...
- [httpd-cvs] 20210330 svn commit: r1073149 [8/13] - in /websites/staging/httpd/trunk/content: ./ security/ security/json/ lists.apache.org · Mailing List https://lists.apache.org/thread.html/r1d201e3da31a2c8aa870c8314623cae...
- [httpd-cvs] 20210330 svn commit: r1073146 [2/3] - in /websites/staging/httpd/trunk/content: ./ security/cvejsontohtml.py security/vulnerabilities-httpd.xml security/vulnerabilities_22.html security/vulnerabilities_24.html lists.apache.org · Mailing List https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34...
- [httpd-cvs] 20210330 svn commit: r1073149 [1/13] - in /websites/staging/httpd/trunk/content: ./ security/ security/json/ lists.apache.org · Mailing List https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e81026...
- [httpd-cvs] 20210603 svn commit: r1075360 [1/3] - in /websites/staging/httpd/trunk/content: ./ security/json/CVE-2021-31618.json security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html lists.apache.org · Mailing List https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b0...
- [httpd-cvs] 20210606 svn commit: r1075467 [1/2] - in /websites/staging/httpd/trunk/content: ./ security/json/CVE-2021-31618.json security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html lists.apache.org · Mailing List https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f...
- [httpd-cvs] 20210606 svn commit: r1075470 [3/4] - in /websites/staging/httpd/trunk/content: ./ security/json/CVE-2020-13938.json security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html lists.apache.org · Mailing List https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff961...
- gossamer-threads.com/lists/apache/dev/401638 gossamer-threads.com · CVE Record http://www.gossamer-threads.com/lists/apache/dev/401638
- bugzilla.redhat.com/show_bug.cgi bugzilla.redhat.com · CVE Record https://bugzilla.redhat.com/show_bug.cgi?id=732928
- oracle.com/technetwork/topics/security/alert-cve-2011-3... oracle.com · CVE Record http://www.oracle.com/technetwork/topics/security/alert-cve-2011-3192...
- issues.apache.org/bugzilla/show_bug.cgi issues.apache.org · CVE Record https://issues.apache.org/bugzilla/show_bug.cgi?id=51714
- oracle.com/technetwork/topics/security/cpuoct2011-33013... oracle.com · CVE Record http://www.oracle.com/technetwork/topics/security/cpuoct2011-330135.html
- blogs.oracle.com/security/entry/security_alert_for_cve_2011 blogs.oracle.com · CVE Record http://blogs.oracle.com/security/entry/security_alert_for_cve_2011
- help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+St... help.ecostruxureit.com · CVE Record https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes...
- oracle.com/technetwork/topics/security/cpujan2012-36630... oracle.com · CVE Record http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html
- apache.org/dist/httpd/Announcement2.2.html apache.org · CVE Record http://www.apache.org/dist/httpd/Announcement2.2.html
- oracle.com/technetwork/topics/security/cpujul2012-39272... oracle.com · CVE Record http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.html
- support.apple.com/kb/HT5002 support.apple.com · CVE Record http://support.apple.com/kb/HT5002
No detection artifacts or sensor request patterns are available for this CVE yet.
Check back as sensor telemetry and scanner integrations are updated.
Virtual Patch
Compensating WAF rules to help reduce exposure to this CVE. Rule content and deployable vendor exports are available with KEVIntel Enterprise.
KEVIntel does not currently have a virtual patch for this CVE. When available, KEVIntel virtual patches ship as deployable ModSecurity, Cloudflare, and AWS WAF rules.
Enterprise feature. Virtual patch rule content and deployable vendor exports (ModSecurity, Cloudflare, AWS WAF) are available to KEVIntel Enterprise users.
CVSS Scores
AV:N/AC:L/Au:N/C:N/I:N/A:C
Exploitation Status
Proof of concept available
Recorded 2018-08-02 11:30:35 UTC · GitHub
Potential Proof of Concepts
These PoCs are unverified and could contain malware. Use at your own risk.
github · Created 2023-09-16 14:01:39 UTC · 0 stars
github · Created 2018-08-02 11:30:35 UTC · 4 stars
Apache Range Header DoS Exploit
Timeline
Key exploitation, disclosure, scanner coverage, and KEV attestation events for this CVE.
-
11:30 UTC almost 8 years ago11:30 UTC · almost 8 years ago
Public PoC available
Public proof-of-concept code published
-
15:00 UTC almost 15 years ago15:00 UTC · almost 15 years ago
CVE published
Vulnerability disclosed publicly
-
00:00 UTC almost 15 years ago00:00 UTC · almost 15 years ago
CVE ID reserved
Identifier reserved by the CNA
Automate This Intelligence with the Pro API
Confidence scoring, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
Pro API Example
GET /api/v2/pro/kevs/CVE-2011-3192
{
"cve_id": "CVE-2011-3192",
"title": "The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, a...",
"affected_vendor": "Apache",
"affected_product": "HTTP Server",
"affected_versions": [
{ "vendor": "...", "product": "...", "status": "affected", "display_label": "..." }
],
"confidence": null,
"cvss_score": 7.8,
"epss_score": null,
"exploit_status": {
"exploited_in_the_wild": false,
"active_exploitation_observed": false
},
"sensor_telemetry": { "...": "Pro API fields" },
"proof_of_concepts": [ "..." ],
"scanner_integrations": [ "..." ]
}