VYPR
Unrated severityNVD Advisory· Published Aug 29, 2011· Updated Apr 29, 2026

CVE-2011-3192

CVE-2011-3192

Description

The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited in the wild in August 2011, a different vulnerability than CVE-2007-0086.

Affected products

15
  • cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*
    Range: >=2.0.35,<2.0.65
  • OpenSUSE/openSUSE2 versions
    cpe:2.3:o:opensuse:opensuse:11.3:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:opensuse:opensuse:11.3:*:*:*:*:*:*:*
    • cpe:2.3:o:opensuse:opensuse:11.4:*:*:*:*:*:*:*
  • cpe:2.3:o:suse:linux_enterprise_server:10:sp2:*:*:-:*:*:*+ 4 more
    • cpe:2.3:o:suse:linux_enterprise_server:10:sp2:*:*:-:*:*:*
    • cpe:2.3:o:suse:linux_enterprise_server:10:sp3:*:*:-:*:*:*
    • cpe:2.3:o:suse:linux_enterprise_server:10:sp4:*:*:-:*:*:*
    • cpe:2.3:o:suse:linux_enterprise_server:11:sp1:*:*:*:-:*:*
    • cpe:2.3:o:suse:linux_enterprise_server:11:sp1:*:*:*:vmware:*:*
  • cpe:2.3:o:suse:linux_enterprise_software_development_kit:10:sp3:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:suse:linux_enterprise_software_development_kit:10:sp3:*:*:*:*:*:*
    • cpe:2.3:o:suse:linux_enterprise_software_development_kit:10:sp4:*:*:*:*:*:*
    • cpe:2.3:o:suse:linux_enterprise_software_development_kit:11:sp1:*:*:*:*:*:*
  • cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:-:*:*:*+ 3 more
    • cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:-:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:10.10:*:*:*:*:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:11.04:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

72

News mentions

0

No linked articles in our index yet.