CVE-2011-3192

PUBLISHED

The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of...

Apache · HTTP Server
PoC available

Recommended Action

Track for updates. Assess relevance to your asset inventory and enrichment workflows.

Confidence
Exploitation Status
PoC available
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
CVSS / EPSS
7.8 High

At a Glance

The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited in the wild in August 2011, a different vulnerability than CVE-2007-0086.

apache
CVE Published
Aug 29, 2011
CVSS
7.8 High
EPSS
Remote Low complexity Unauthenticated

Affected Versions

Vendor Product Version Status
n/a
n/a

n/a

Affected

CVE References

  • RHSA-2011:1369 redhat.com · Vendor Advisory http://www.redhat.com/support/errata/RHSA-2011-1369.html
  • RHSA-2011:1329 redhat.com · Vendor Advisory http://www.redhat.com/support/errata/RHSA-2011-1329.html
  • HPSBUX02707 marc.info · Vendor Advisory http://marc.info/?l=bugtraq&m=131731002122529&w=2
  • SUSE-SU-2011:1010 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00011...
  • SSRT100966 marc.info · Vendor Advisory http://marc.info/?l=bugtraq&m=134987041210674&w=2
Show 67 more references

Recommended Actions

  • Track for updates. Assess relevance to your asset inventory and enrichment workflows.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.