CVE-2011-3192 EXPLOIT
7.8
HIGH · CVSS 2.0 · EPSS 98.8% (pctl 100)
Patch early
A public exploit exists.
Description
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited in the wild in August 2011, a different vulnerability than CVE-2007-0086.
Scoring
| CVSS | 7.8 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
| EPSS | 98.83% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-400 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2011-08-29 |
| Last modified | 2026-06-16 |
Affected (5)
| Vendor | Product |
|---|---|
| apache | http server |
| canonical | ubuntu linux |
| opensuse | opensuse |
| suse | linux enterprise server |
| suse | linux enterprise software development kit |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Apache - Denial of Service | 2011-12-09 |
| exploit-db | Apache - Remote Memory Exhaustion (Denial of Service) | 2011-08-19 |
References
- http://archives.neohapsis.com/archives/fulldisclosure/2011-08/0285.html
- http://blogs.oracle.com/security/entry/security_alert_for_cve_2011
- http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html
- http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00006.html
- http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00009.html
- http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00011.html
- http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00008.html
- http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00011.html
- http://mail-archives.apache.org/mod_mbox/httpd-announce/201108.mbox/%3c20110824161640.122D387DD%40minotaur.apache.org%3e
- http://mail-archives.apache.org/mod_mbox/httpd-dev/201108.mbox/%3cCAAPSnn2PO-d-C4nQt_TES2RRWiZr7urefhTKPWBC1b+K1Dqc7g%40mail.gmail.com%3e
- http://marc.info/?l=bugtraq&m=131551295528105&w=2
- http://marc.info/?l=bugtraq&m=131731002122529&w=2
- http://marc.info/?l=bugtraq&m=132033751509019&w=2
- http://marc.info/?l=bugtraq&m=133477473521382&w=2
- http://marc.info/?l=bugtraq&m=133951357207000&w=2
- http://marc.info/?l=bugtraq&m=134987041210674&w=2
- http://osvdb.org/74721
- http://seclists.org/fulldisclosure/2011/Aug/175
- http://secunia.com/advisories/45606
→ the Explorer · watch your stack · NVD