CVE-2006-3747 EXPLOIT
7.6
HIGH · CVSS 2.0 · EPSS 96.6% (pctl 100)
Patch early
A public exploit exists.
Description
Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2, when RewriteEngine is enabled, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted URLs that are not properly handled using certain rewrite rules.
Scoring
| CVSS | 7.6 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:H/Au:N/C:C/I:C/A:C |
| EPSS | 96.58% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-189 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2006-07-28 |
| Last modified | 2026-06-16 |
Affected (3)
| Vendor | Product |
|---|---|
| apache | http server |
| canonical | ubuntu linux |
| debian | debian linux |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Apache mod_rewrite - LDAP protocol Buffer Overflow (Metasploit) | 2010-02-15 |
| exploit-db | Apache 2.0.58 mod_rewrite (Windows 2003) - Remote Overflow | 2007-05-26 |
| exploit-db | Apache mod_rewrite (Windows x86) - Off-by-One Remote Overflow | 2007-04-07 |
| exploit-db | Apache < 1.3.37/2.0.59/2.2.3 mod_rewrite - Remote Overflow | 2006-08-21 |
References
- http://docs.info.apple.com/article.html?artnum=307562
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01118771
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01428449
- http://kbase.redhat.com/faq/FAQ_68_8653.shtm
- http://lists.apple.com/archives/security-announce/2008//May/msg00001.html
- http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/048267.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/048271.html
- http://lwn.net/Alerts/194228/
- http://marc.info/?l=bugtraq&m=130497311408250&w=2
- http://secunia.com/advisories/21197
- http://secunia.com/advisories/21241
- http://secunia.com/advisories/21245
- http://secunia.com/advisories/21247
- http://secunia.com/advisories/21266
- http://secunia.com/advisories/21273
- http://secunia.com/advisories/21284
- http://secunia.com/advisories/21307
- http://secunia.com/advisories/21313
- http://secunia.com/advisories/21315
→ the Explorer · watch your stack · NVD