PT-2011-3482 · Apache+1 · Apache Http Server+2

Chris

·

Published

2011-05-24

·

Updated

2024-06-15

·

CVE-2011-1928

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Apache Portable Runtime (APR) library versions 1.4.3 through 1.4.4 Apache HTTP Server version 2.2.18
Description The issue allows remote attackers to cause a denial of service, resulting in an infinite loop, via a URI that does not match certain types of wildcard patterns. This can be demonstrated by attacks against mod autoindex in httpd when a /*/WEB-INF/ configuration pattern is used.
Recommendations For Apache Portable Runtime (APR) library versions 1.4.3 and 1.4.4, consider updating to a version that includes a correct fix for the issue. For Apache HTTP Server version 2.2.18, consider updating to a version that includes a correct fix for the issue. As a temporary workaround, consider restricting access to the mod autoindex module in httpd to minimize the risk of exploitation.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-1928
DSA-2237-2
OPENSUSE-SU-2024:10063-1
OPENSUSE-SU-2024:11596-1
RHSA-2011:0844
RHSA-2011_0844

Affected Products

Apache Http Server
Apache Portable Runtime
Red Hat