Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2, when RewriteEngine is enabled, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted URLs that are not properly handled using certain rewrite rules
Published Jul 28, 2006
7.6
HIGHCVSS 2.0
EPSS 96.58%
Description
Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2, when RewriteEngine is enabled, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted URLs that are not properly handled using certain rewrite rules.
Affected products
No data.
Configuration 1
- ≥ 1.3.28 · < 1.3.37
- ≥ 2.0.46 · < 2.0.59
- ≥ 2.2.0 · < 2.2.3
Configuration 2
- 5.04
- 5.10
- 6.06
Configuration 3
- 3.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
The ability to exploit this issue is dependent on the stack layout for a particular compiled version of mod_rewrite. If the compiler has added padding to the stack immediately after the buffer being overwritten, this issue can not be exploited, and Apache httpd will continue operating normally. The Red Hat Security Response Team analyzed Red Hat Enterprise Linux 3 and Red Hat Enterprise Linux 4 binaries for all architectures as shipped by Red Hat and determined that these versions cannot be exploited. This issue does not affect the version of Apache httpd as supplied with Red Hat Enterprise Linux 2.1
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:H/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (18 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 96.58% (0.96578) | 99.88th | v5 (v2026.06.15) |
| Jun 15, 2026 | 95.65% (0.95647) | 99.86th | v5 (v2026.06.15) |
| Apr 25, 2026 | 90.02% (0.90024) | 99.59th | v4 (v2025.03.14) |
| Mar 17, 2025 | 92.74% (0.92739) | 99.75th | v4 (v2025.03.14) |
| Dec 17, 2024 | 93.52% (0.93515) | 99.31th | v3 (v2023.03.01) |
| Dec 12, 2024 | 97.45% (0.97447) | 99.97th | v3 (v2023.03.01) |
| Jun 17, 2024 | 97.43% (0.97428) | 99.94th | v3 (v2023.03.01) |
| Apr 2, 2024 | 97.40% (0.97401) | 99.92th | v3 (v2023.03.01) |
| Feb 7, 2024 | 97.44% (0.97444) | 99.94th | v3 (v2023.03.01) |
| Nov 1, 2023 | 97.44% (0.97436) | 99.93th | v3 (v2023.03.01) |
| Sep 23, 2023 | 97.41% (0.97408) | 99.90th | v3 (v2023.03.01) |
| Jun 1, 2023 | 97.44% (0.97444) | 99.91th | v3 (v2023.03.01) |
| May 8, 2023 | 97.45% (0.97450) | 99.91th | v3 (v2023.03.01) |
| Apr 24, 2023 | 97.46% (0.97458) | 99.92th | v3 (v2023.03.01) |
| Mar 17, 2023 | 97.50% (0.97502) | 99.96th | v3 (v2023.03.01) |
| Mar 7, 2023 | 97.46% (0.97463) | 99.91th | v3 (v2023.03.01) |
| Mar 6, 2023 | 79.46% (0.79461) | 99.48th | v2 (v2022.01.01) |
| Feb 4, 2022 | 79.46% (0.79461) | 99.38th | v2 (v2022.01.01) |
References (93)
- http://docs.info.apple.com/article.html?artnum=307562 x_refsource_CONFIRMThird Party Advisory
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01118771 vendor-advisoryx_refsource_HPThird Party Advisory
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01428449 vendor-advisoryx_refsource_HPThird Party Advisory
- http://kbase.redhat.com/faq/FAQ_68_8653.shtm x_refsource_MISCThird Party Advisory
- http://lists.apple.com/archives/security-announce/2008//May/msg00001.html vendor-advisoryx_refsource_APPLEMailing ListThird Party Advisory
- http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html vendor-advisoryx_refsource_APPLEMailing ListThird Party Advisory
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/048267.html mailing-listx_refsource_FULLDISCThird Party Advisory
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/048271.html mailing-listx_refsource_FULLDISCMailing ListThird Party Advisory
- http://lwn.net/Alerts/194228/ vendor-advisoryx_refsource_TRUSTIXMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=130497311408250&w=2 vendor-advisoryx_refsource_HPMailing ListThird Party Advisory
- http://secunia.com/advisories/21197 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/21241 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/21245 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/21247 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/21266 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/21273 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/21284 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/21307 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/21313 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/21315 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/21346 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/21478 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/21509 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/22262 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/22368 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/22388 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/22523 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/23028 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/23260 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/26329 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/29420 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/29849 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/30430 third-party-advisoryx_refsource_SECUNIABroken Link
- http://security.gentoo.org/glsa/glsa-200608-01.xml vendor-advisoryx_refsource_GENTOOThird Party Advisory
- http://securityreason.com/securityalert/1312 third-party-advisoryx_refsource_SREASONThird Party Advisory
- http://securitytracker.com/id?1016601 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102662-1 vendor-advisoryx_refsource_SUNALERTBroken Link
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102663-1 vendor-advisoryx_refsource_SUNALERTBroken Link
- http://svn.apache.org/viewvc?view=rev&revision=426144 x_refsource_MISCVendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg1PK29154 vendor-advisoryx_refsource_AIXAPARThird Party Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg1PK29156 vendor-advisoryx_refsource_AIXAPARThird Party Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg24013080 vendor-advisoryx_refsource_AIXAPARThird Party Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg27007951 x_refsource_CONFIRMThird Party Advisory
- http://www.apache.org/dist/httpd/Announcement2.0.html x_refsource_CONFIRMPatchVendor Advisory
- http://www.debian.org/security/2006/dsa-1131 vendor-advisoryx_refsource_DEBIANPatchThird Party Advisory
- http://www.debian.org/security/2006/dsa-1132 vendor-advisoryx_refsource_DEBIANPatchThird Party Advisory
- http://www.kb.cert.org/vuls/id/395412 third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:133 vendor-advisoryx_refsource_MANDRIVABroken Link
- http://www.novell.com/linux/security/advisories/2006_43_apache.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.015-apache.html vendor-advisoryx_refsource_OPENPKGThird Party Advisory
- http://www.osvdb.org/27588 vdb-entryx_refsource_OSVDBBroken Link
- http://www.securityfocus.com/archive/1/441485/100/0/threaded mailing-listx_refsource_BUGTRAQThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/archive/1/441487/100/0/threaded mailing-listx_refsource_BUGTRAQThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/archive/1/441526/100/200/threaded mailing-listx_refsource_BUGTRAQThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/archive/1/443870/100/0/threaded mailing-listx_refsource_BUGTRAQThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/archive/1/445206/100/0/threaded vendor-advisoryx_refsource_HPThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/archive/1/450321/100/0/threaded vendor-advisoryx_refsource_HPThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/19204 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/usn-328-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.us-cert.gov/cas/techalerts/TA08-150A.html third-party-advisoryx_refsource_CERTThird Party AdvisoryUS Government Resource
- http://www.vupen.com/english/advisories/2006/3017 vdb-entryx_refsource_VUPENPermissions Required
- http://www.vupen.com/english/advisories/2006/3264 vdb-entryx_refsource_VUPENPermissions Required
- http://www.vupen.com/english/advisories/2006/3282 vdb-entryx_refsource_VUPENPermissions Required
- http://www.vupen.com/english/advisories/2006/3884 vdb-entryx_refsource_VUPENPermissions Required
- http://www.vupen.com/english/advisories/2006/3995 vdb-entryx_refsource_VUPENPermissions Required
- http://www.vupen.com/english/advisories/2006/4015 vdb-entryx_refsource_VUPENPermissions Required
- http://www.vupen.com/english/advisories/2006/4207 vdb-entryx_refsource_VUPENPermissions Required
- http://www.vupen.com/english/advisories/2006/4300 vdb-entryx_refsource_VUPENPermissions Required
- http://www.vupen.com/english/advisories/2006/4868 vdb-entryx_refsource_VUPENPermissions Required
- http://www.vupen.com/english/advisories/2007/2783 vdb-entryx_refsource_VUPENPermissions Required
- http://www.vupen.com/english/advisories/2008/0924/references vdb-entryx_refsource_VUPENPermissions Required
- http://www.vupen.com/english/advisories/2008/1246/references vdb-entryx_refsource_VUPENPermissions Required
- http://www.vupen.com/english/advisories/2008/1697 vdb-entryx_refsource_VUPENPermissions Required
- http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=3117 x_refsource_CONFIRMThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2006-3747 Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28063 vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry
- https://issues.rpath.com/browse/RPL-538 x_refsource_CONFIRMBroken Link
- https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r652fc951306cdeca5a276e2021a34878a76695a9f3cfb6490b4a6840%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rafd145ba6cd0a4ced113a5823cdaff45aeb36eb09855b216401c66d6%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/reb542d2038e9c331506e0cbff881b47e40fbe2bd93ff00979e60cdf7%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://nvd.nist.gov/vuln/detail/CVE-2006-3747
- https://www.cve.org/CVERecord?id=CVE-2006-3747
Change history (0)
No recorded changes yet.