PT-2011-4554 · Apache+3 · Apache Http Server+3

Published

2011-11-30

·

Updated

2023-02-13

·

CVE-2011-3639

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.0.x through 2.0.64 Apache HTTP Server versions 2.2.x before 2.2.18
Description The issue arises from the mod proxy module's improper interaction with RewriteRule and ProxyPassMatch pattern matches when configured as a reverse proxy. This allows remote attackers to send requests to intranet servers by using the HTTP/0.9 protocol with a malformed URI containing an initial @ (at sign) character.
Recommendations For Apache HTTP Server versions 2.0.x through 2.0.64, update to a version that includes the complete fix for the issue. For Apache HTTP Server versions 2.2.x before 2.2.18, update to version 2.2.18 or later. As a temporary workaround, consider restricting access to the mod proxy module until a patch is available.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

CESA-2012_0128
CVE-2011-3639
DSA-2405-1
RHSA-2012:0128
RHSA-2012:0323
RHSA-2012_0128
RHSA-2012_0323

Affected Products

Apache Http Server
Centos
Red Hat
Suse