Back

HIGH

httpd: multiple ranges DoS

Published Aug 29, 2011

Description

The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited in the wild in August 2011, a different vulnerability than CVE-2007-0086.

Affected products

Remediation

Red Hat statement

Before updated packages are deployed, users can deploy configuration changes to mitigate this flaw: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-3192#c18

Metrics

References (75)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 29, 2011
Updated Aug 6, 2024
Reserved Aug 19, 2011
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Aug 20, 2011