Lucene search

K
httpdApache Team FoundationHTTPD:49F10A242AB057B651259425C3E680F4
HistoryDec 25, 2008 - 12:00 a.m.

Apache Httpd < 2.2.12 : APR-util heap underwrite

2008-12-2500:00:00
Apache Team Foundation
httpd.apache.org
16

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

EPSS

0.036

Percentile

91.7%

A heap-based underwrite flaw was found in the way the bundled copy of the APR-util library created compiled forms of particular search patterns. An attacker could formulate a specially-crafted search keyword, that would overwrite arbitrary heap memory locations when processed by the pattern preparation engine.

Affected configurations

Vulners
Node
apacheapache_httpdMatch2.2.11
OR
apacheapache_httpdMatch2.2.10
OR
apacheapache_httpdMatch2.2.9
OR
apacheapache_httpdMatch2.2.8
OR
apacheapache_httpdMatch2.2.6
OR
apacheapache_httpdMatch2.2.5
OR
apacheapache_httpdMatch2.2.4
OR
apacheapache_httpdMatch2.2.3
OR
apacheapache_httpdMatch2.2.2
OR
apacheapache_httpdMatch2.2.0
VendorProductVersionCPE
apacheapache_httpd2.2.11cpe:2.3:a:apache:apache_httpd:2.2.11:*:*:*:*:*:*:*
apacheapache_httpd2.2.10cpe:2.3:a:apache:apache_httpd:2.2.10:*:*:*:*:*:*:*
apacheapache_httpd2.2.9cpe:2.3:a:apache:apache_httpd:2.2.9:*:*:*:*:*:*:*
apacheapache_httpd2.2.8cpe:2.3:a:apache:apache_httpd:2.2.8:*:*:*:*:*:*:*
apacheapache_httpd2.2.6cpe:2.3:a:apache:apache_httpd:2.2.6:*:*:*:*:*:*:*
apacheapache_httpd2.2.5cpe:2.3:a:apache:apache_httpd:2.2.5:*:*:*:*:*:*:*
apacheapache_httpd2.2.4cpe:2.3:a:apache:apache_httpd:2.2.4:*:*:*:*:*:*:*
apacheapache_httpd2.2.3cpe:2.3:a:apache:apache_httpd:2.2.3:*:*:*:*:*:*:*
apacheapache_httpd2.2.2cpe:2.3:a:apache:apache_httpd:2.2.2:*:*:*:*:*:*:*
apacheapache_httpd2.2.0cpe:2.3:a:apache:apache_httpd:2.2.0:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

EPSS

0.036

Percentile

91.7%