CVE-2011-4415

CVSS V2 Low 1.2 CVSS V3 None
Description
The ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, does not restrict the size of values of environment variables, which allows local users to cause a denial of service (memory consumption or NULL pointer dereference) via a .htaccess file with a crafted SetEnvIf directive, in conjunction with a crafted HTTP request header, related to (1) the "len +=" statement and (2) the apr_pcalloc function call, a different vulnerability than CVE-2011-3607.
Overview
  • CVE ID
  • CVE-2011-4415
  • Assigner
  • cve@mitre.org
  • Vulnerability Status
  • Modified
  • Published Version
  • 2011-11-08T11:55:05
  • Last Modified Date
  • 2012-07-03T04:04:31
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:apache:http_server:2.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.0.9:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.0.28:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.0.28:beta:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.0.32:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.0.32:beta:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.0.34:beta:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.0.35:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.0.36:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.0.37:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.0.38:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.0.39:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.0.40:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.0.41:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.0.42:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.0.43:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.0.44:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.0.45:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.0.46:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.0.47:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.0.48:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.0.49:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.0.50:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.0.51:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.0.52:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.0.53:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.0.54:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.0.55:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.0.56:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.0.57:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.0.58:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.0.59:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.0.60:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.0.61:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.0.63:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.0.64:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.2.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.2.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.2.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.2.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.2.4:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.2.6:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.2.8:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.2.9:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.2.10:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.2.11:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.2.12:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.2.13:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.2.14:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.2.15:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.2.16:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.2.18:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.2.19:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.2.20:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.2.21:*:*:*:*:*:*:* 1 OR
CVSS Version 2
  • Version
  • 2.0
  • Vector String
  • AV:L/AC:H/Au:N/C:N/I:N/A:P
  • Access Vector
  • LOCAL
  • Access Compatibility
  • HIGH
  • Authentication
  • NONE
  • Confidentiality Impact
  • NONE
  • Integrity Impact
  • NONE
  • Availability Impact
  • PARTIAL
  • Base Score
  • 1.2
  • Severity
  • LOW
  • Exploitability Score
  • 1.9
  • Impact Score
  • 2.9
History
Created Old Value New Value Data Type Notes
2022-05-10 10:54:04 Added to TrackCVE