Lucene search

K
f5F5F5:K16908
HistoryJul 23, 2015 - 12:00 a.m.

K16908 : Apache HTTPD vulnerability CVE-2011-4415

2015-07-2300:00:00
my.f5.com
43

AI Score

5.8

Confidence

Low

EPSS

0.001

Percentile

26.5%

Security Advisory Description

The ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, does not restrict the size of values of environment variables, which allows local users to cause a denial of service (memory consumption or NULL pointer dereference) via a .htaccess file with a crafted SetEnvIf directive, in conjunction with a crafted HTTP request header, related to (1) the “len +=” statement and (2) the apr_pcalloc function call, a different vulnerability than CVE-2011-3607. (CVE-2011-4415)

Impact

A local attacker may be able to cause a denial-of-service (DoS).