PT-2011-2336 · Freebsd+8 · Freebsd+9

Publicado

2011-05-10

·

Atualizado

2024-06-15

·

CVE-2011-0419

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Apache Portable Runtime (APR) library versions prior to 1.4.3 Apache HTTP Server versions prior to 2.2.18 NetBSD version 5.1 OpenBSD version 4.8 FreeBSD (affected versions not specified) Apple Mac OS X version 10.6 Oracle Solaris version 10 Android (affected versions not specified)
Description A stack consumption issue in the fnmatch implementation allows context-dependent attackers to cause a denial of service via *? sequences in the first argument, potentially leading to CPU and memory consumption. This issue can be exploited by sending carefully crafted requests, particularly against mod autoindex in httpd, when it is enabled and a directory contains files with sufficiently long names.
Recommendations For Apache Portable Runtime (APR) library versions prior to 1.4.3, update to release 1.4.5 or later. For Apache HTTP Server versions prior to 2.2.18, update to release 2.2.19 or later, which bundles APR 1.4.5, or update to release 2.0.65, which bundles APR 0.9.20. As a temporary workaround, consider setting the 'IgnoreClient' option to the 'IndexOptions' directive to disable processing of client-supplied request query arguments and prevent this attack.

Exploit

Correção

DoS

Allocation of Resources Without Limits

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-0419
DSA-2237-2
HPSBUX02702
HPSBUX02707
OPENSUSE-SU-2024:10063-1
OPENSUSE-SU-2024:11596-1
RHSA-2011:0507
RHSA-2011:0897
RHSA-2011_0507

Produtos afetados

Android
Apache Http Server
Apache Portable Runtime
Freebsd
Hp-Ux
Macos X
Netbsd
Openbsd
Oracle Solaris
Red Hat