PT-2011-2336 · Freebsd+8 · Freebsd+9

Published

2011-05-10

·

Updated

2024-06-15

·

CVE-2011-0419

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Apache Portable Runtime (APR) library versions prior to 1.4.3 Apache HTTP Server versions prior to 2.2.18 NetBSD version 5.1 OpenBSD version 4.8 FreeBSD (affected versions not specified) Apple Mac OS X version 10.6 Oracle Solaris version 10 Android (affected versions not specified)
Description A stack consumption issue in the fnmatch implementation allows context-dependent attackers to cause a denial of service via *? sequences in the first argument, potentially leading to CPU and memory consumption. This issue can be exploited by sending carefully crafted requests, particularly against mod autoindex in httpd, when it is enabled and a directory contains files with sufficiently long names.
Recommendations For Apache Portable Runtime (APR) library versions prior to 1.4.3, update to release 1.4.5 or later. For Apache HTTP Server versions prior to 2.2.18, update to release 2.2.19 or later, which bundles APR 1.4.5, or update to release 2.0.65, which bundles APR 0.9.20. As a temporary workaround, consider setting the 'IgnoreClient' option to the 'IndexOptions' directive to disable processing of client-supplied request query arguments and prevent this attack.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-0419
DSA-2237-2
HPSBUX02702
HPSBUX02707
OPENSUSE-SU-2024:10063-1
OPENSUSE-SU-2024:11596-1
RHSA-2011:0507
RHSA-2011:0897
RHSA-2011_0507

Affected Products

Android
Apache Http Server
Apache Portable Runtime
Freebsd
Hp-Ux
Macos X
Netbsd
Openbsd
Oracle Solaris
Red Hat