httpd: multiple ranges DoS
Published Aug 29, 2011
7.8
HIGHCVSS 2.0
EPSS 98.83%
Description
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited in the wild in August 2011, a different vulnerability than CVE-2007-0086.
Affected products
No data.
Configuration 1
- ≥ 2.0.35 · < 2.0.65
- ≥ 2.2.0 · < 2.2.20
Configuration 2
- 11.3
- 11.4
- 10
- 10
- 10
- 11
- 11
- 10
- 10
- 11
Configuration 3
- 8.04
- 10.04
- 10.10
- 11.04
No data.
Red Hat Enterprise Linux 3 Extended Lifecycle Support
httpd-0:2.0.46-78.ent
Fixed · RHSA-2011:1300
Red Hat Enterprise Linux 4
httpd-0:2.0.52-48.ent
Fixed · RHSA-2011:1245
Red Hat Enterprise Linux 5
httpd-0:2.2.3-45.el5_6.2
Fixed · RHSA-2011:1294
Red Hat Enterprise Linux 5
httpd-0:2.2.3-53.el5_7.1
Fixed · RHSA-2011:1245
Red Hat Enterprise Linux 5.3 Long Life
httpd-0:2.2.3-22.el5_3.3
Fixed · RHSA-2011:1294
Red Hat Enterprise Linux 6
httpd-0:2.2.15-9.el6_1.2
Fixed · RHSA-2011:1245
Red Hat Enterprise Linux 6.0 EUS - Server Only
httpd-0:2.2.15-5.el6_0.1
Fixed · RHSA-2011:1294
Red Hat JBoss Enterprise Web Server 1 for RHEL 5
httpd-0:2.2.17-14.1.ep5.el5
Fixed · RHSA-2011:1329
Red Hat JBoss Enterprise Web Server 1 for RHEL 6
httpd-0:2.2.17-13.2.ep5.el6
Fixed · RHSA-2011:1329
Red Hat JBoss Web Server 1.0
n/a
Fixed · RHSA-2011:1330
Red Hat Directory Server 8
httpd
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 3 Extended Lifecycle Support | httpd-0:2.0.46-78.ent | Fixed | RHSA-2011:1300 |
| Red Hat Enterprise Linux 4 | httpd-0:2.0.52-48.ent | Fixed | RHSA-2011:1245 |
| Red Hat Enterprise Linux 5 | httpd-0:2.2.3-45.el5_6.2 | Fixed | RHSA-2011:1294 |
| Red Hat Enterprise Linux 5 | httpd-0:2.2.3-53.el5_7.1 | Fixed | RHSA-2011:1245 |
| Red Hat Enterprise Linux 5.3 Long Life | httpd-0:2.2.3-22.el5_3.3 | Fixed | RHSA-2011:1294 |
| Red Hat Enterprise Linux 6 | httpd-0:2.2.15-9.el6_1.2 | Fixed | RHSA-2011:1245 |
| Red Hat Enterprise Linux 6.0 EUS - Server Only | httpd-0:2.2.15-5.el6_0.1 | Fixed | RHSA-2011:1294 |
| Red Hat JBoss Enterprise Web Server 1 for RHEL 5 | httpd-0:2.2.17-14.1.ep5.el5 | Fixed | RHSA-2011:1329 |
| Red Hat JBoss Enterprise Web Server 1 for RHEL 6 | httpd-0:2.2.17-13.2.ep5.el6 | Fixed | RHSA-2011:1329 |
| Red Hat JBoss Web Server 1.0 | n/a | Fixed | RHSA-2011:1330 |
| Red Hat Directory Server 8 | httpd | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Before updated packages are deployed, users can deploy configuration changes to mitigate this flaw: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-3192#c18
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (18 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 98.83% (0.98828) | 99.93th | v5 (v2026.06.15) |
| Jun 15, 2026 | 98.95% (0.98945) | 99.92th | v5 (v2026.06.15) |
| Feb 18, 2026 | 91.18% (0.91180) | 99.63th | v4 (v2025.03.14) |
| May 1, 2025 | 92.56% (0.92556) | 99.73th | v4 (v2025.03.14) |
| Mar 17, 2025 | 93.57% (0.93571) | 99.83th | v4 (v2025.03.14) |
| Dec 12, 2024 | 96.31% (0.96307) | 99.61th | v3 (v2023.03.01) |
| Jun 7, 2024 | 96.31% (0.96315) | 99.55th | v3 (v2023.03.01) |
| Apr 18, 2024 | 96.39% (0.96385) | 99.54th | v3 (v2023.03.01) |
| Feb 27, 2024 | 96.17% (0.96165) | 99.46th | v3 (v2023.03.01) |
| Nov 8, 2023 | 96.56% (0.96558) | 99.49th | v3 (v2023.03.01) |
| Sep 17, 2023 | 97.48% (0.97478) | 99.95th | v3 (v2023.03.01) |
| Jul 25, 2023 | 97.47% (0.97469) | 99.94th | v3 (v2023.03.01) |
| Mar 29, 2023 | 97.48% (0.97479) | 99.94th | v3 (v2023.03.01) |
| Mar 7, 2023 | 97.49% (0.97489) | 99.94th | v3 (v2023.03.01) |
| Mar 6, 2023 | 80.49% (0.80492) | 99.52th | v2 (v2022.01.01) |
| Jan 4, 2023 | 80.49% (0.80492) | 99.51th | v2 (v2022.01.01) |
| Oct 19, 2022 | 86.78% (0.86778) | 99.71th | v2 (v2022.01.01) |
| Feb 4, 2022 | 90.63% (0.90634) | 99.84th | v2 (v2022.01.01) |
References (75)
- http://archives.neohapsis.com/archives/fulldisclosure/2011-08/0285.html mailing-listx_refsource_FULLDISCBroken Link
- http://blogs.oracle.com/security/entry/security_alert_for_cve_2011 x_refsource_CONFIRMBroken Link
- http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html vendor-advisoryx_refsource_APPLEBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00006.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00009.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00010.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00011.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00008.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00011.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://mail-archives.apache.org/mod_mbox/httpd-announce/201108.mbox/%3c20110824161640.122D387DD%40minotaur.apache.org%3e mailing-listx_refsource_MLIST
- http://mail-archives.apache.org/mod_mbox/httpd-dev/201108.mbox/%3cCAAPSnn2PO-d-C4nQt_TES2RRWiZr7urefhTKPWBC1b+K1Dqc7g%40mail.gmail.com%3e mailing-listx_refsource_MLIST
- http://marc.info/?l=bugtraq&m=131551295528105&w=2 vendor-advisoryx_refsource_HPIssue TrackingMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=131731002122529&w=2 vendor-advisoryx_refsource_HPIssue TrackingMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=132033751509019&w=2 vendor-advisoryx_refsource_HPIssue TrackingMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=133477473521382&w=2 vendor-advisoryx_refsource_HPIssue TrackingMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=133951357207000&w=2 vendor-advisoryx_refsource_HPIssue TrackingMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=134987041210674&w=2 vendor-advisoryx_refsource_HPIssue TrackingMailing List
- http://osvdb.org/74721 vdb-entryx_refsource_OSVDBBroken Link
- http://seclists.org/fulldisclosure/2011/Aug/175 mailing-listx_refsource_FULLDISCExploitMailing ListThird Party Advisory
- http://secunia.com/advisories/45606 third-party-advisoryx_refsource_SECUNIANot ApplicableVendor Advisory
- http://secunia.com/advisories/45937 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/46000 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/46125 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/46126 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://securitytracker.com/id?1025960 vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry
- http://support.apple.com/kb/HT5002 x_refsource_CONFIRMThird Party Advisory
- http://www.apache.org/dist/httpd/Announcement2.2.html x_refsource_CONFIRMBroken Link
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080b90d73.shtml vendor-advisoryx_refsource_CISCOThird Party Advisory
- http://www.exploit-db.com/exploits/17696 exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
- http://www.gossamer-threads.com/lists/apache/dev/401638 x_refsource_CONFIRMThird Party Advisory
- http://www.kb.cert.org/vuls/id/405811 third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:130 vendor-advisoryx_refsource_MANDRIVABroken Link
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:150 vendor-advisoryx_refsource_MANDRIVABroken Link
- http://www.oracle.com/technetwork/topics/security/alert-cve-2011-3192-485304.html x_refsource_CONFIRMThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html x_refsource_CONFIRMThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.html x_refsource_CONFIRMThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpuoct2011-330135.html x_refsource_CONFIRMThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2011-1245.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2011-1294.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2011-1300.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2011-1329.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2011-1330.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2011-1369.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.securityfocus.com/bid/49303 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-1199-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2011-3192 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=732928 x_refsource_CONFIRMExploitIssue TrackingThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/69396 vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry
- https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0 x_refsource_CONFIRMThird Party Advisory
- https://issues.apache.org/bugzilla/show_bug.cgi?id=51714 x_refsource_CONFIRMExploitIssue TrackingVendor Advisory
- https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r1d201e3da31a2c8aa870c8314623caef7debd74a13d0f25205e26f15%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r688df6f16f141e966a0a47f817e559312b3da27886f59116a94b273d%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/re2e23465bbdb17ffe109d21b4f192e6b58221cd7aa8797d530b4cd75%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://nvd.nist.gov/vuln/detail/CVE-2011-3192
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14762 vdb-entrysignaturex_refsource_OVALThird Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14824 vdb-entrysignaturex_refsource_OVALThird Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18827 vdb-entrysignaturex_refsource_OVALThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2011-3192
Change history (0)
No recorded changes yet.