CVE-2011-3639
Summary
| CVE | CVE-2011-3639 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-11-30 04:05:58 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The mod_proxy module in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x before 2.2.18, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers by using the HTTP/0.9 protocol with a malformed URI containing an initial @ (at sign) character. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-3368. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Http Server | 2.0.11 | All | All | All |
| Application | Apache | Http Server | 2.0.12 | All | All | All |
| Application | Apache | Http Server | 2.0.13 | All | All | All |
| Application | Apache | Http Server | 2.0.14 | All | All | All |
| Application | Apache | Http Server | 2.0.15 | All | All | All |
| Application | Apache | Http Server | 2.0.16 | All | All | All |
| Application | Apache | Http Server | 2.0.17 | All | All | All |
| Application | Apache | Http Server | 2.0.18 | All | All | All |
| Application | Apache | Http Server | 2.0.19 | All | All | All |
| Application | Apache | Http Server | 2.0.20 | All | All | All |
| Application | Apache | Http Server | 2.0.21 | All | All | All |
| Application | Apache | Http Server | 2.0.22 | All | All | All |
| Application | Apache | Http Server | 2.0.23 | All | All | All |
| Application | Apache | Http Server | 2.0.24 | All | All | All |
| Application | Apache | Http Server | 2.0.25 | All | All | All |
| Application | Apache | Http Server | 2.0.26 | All | All | All |
| Application | Apache | Http Server | 2.0.27 | All | All | All |
| Application | Apache | Http Server | 2.0.28 | All | All | All |
| Application | Apache | Http Server | 2.0.29 | All | All | All |
| Application | Apache | Http Server | 2.0.30 | All | All | All |
| Application | Apache | Http Server | 2.0.31 | All | All | All |
| Application | Apache | Http Server | 2.0.32 | All | All | All |
| Application | Apache | Http Server | 2.0.33 | All | All | All |
| Application | Apache | Http Server | 2.0.34 | All | All | All |
| Application | Apache | Http Server | 2.0.35 | All | All | All |
| Application | Apache | Http Server | 2.0.36 | All | All | All |
| Application | Apache | Http Server | 2.0.37 | All | All | All |
| Application | Apache | Http Server | 2.0.38 | All | All | All |
| Application | Apache | Http Server | 2.0.39 | All | All | All |
| Application | Apache | Http Server | 2.0.40 | All | All | All |
| Application | Apache | Http Server | 2.0.41 | All | All | All |
| Application | Apache | Http Server | 2.0.42 | All | All | All |
| Application | Apache | Http Server | 2.0.43 | All | All | All |
| Application | Apache | Http Server | 2.0.44 | All | All | All |
| Application | Apache | Http Server | 2.0.45 | All | All | All |
| Application | Apache | Http Server | 2.0.46 | All | All | All |
| Application | Apache | Http Server | 2.0.47 | All | All | All |
| Application | Apache | Http Server | 2.0.48 | All | All | All |
| Application | Apache | Http Server | 2.0.49 | All | All | All |
| Application | Apache | Http Server | 2.0.50 | All | All | All |
| Application | Apache | Http Server | 2.0.51 | All | All | All |
| Application | Apache | Http Server | 2.0.52 | All | All | All |
| Application | Apache | Http Server | 2.0.53 | All | All | All |
| Application | Apache | Http Server | 2.0.54 | All | All | All |
| Application | Apache | Http Server | 2.0.55 | All | All | All |
| Application | Apache | Http Server | 2.0.56 | All | All | All |
| Application | Apache | Http Server | 2.0.57 | All | All | All |
| Application | Apache | Http Server | 2.0.58 | All | All | All |
| Application | Apache | Http Server | 2.0.59 | All | All | All |
| Application | Apache | Http Server | 2.0.61 | All | All | All |
| Application | Apache | Http Server | 2.0.63 | All | All | All |
| Application | Apache | Http Server | 2.2.0 | All | All | All |
| Application | Apache | Http Server | 2.2.1 | All | All | All |
| Application | Apache | Http Server | 2.2.10 | All | All | All |
| Application | Apache | Http Server | 2.2.11 | All | All | All |
| Application | Apache | Http Server | 2.2.12 | All | All | All |
| Application | Apache | Http Server | 2.2.13 | All | All | All |
| Application | Apache | Http Server | 2.2.14 | All | All | All |
| Application | Apache | Http Server | 2.2.15 | All | All | All |
| Application | Apache | Http Server | 2.2.16 | All | All | All |
| Application | Apache | Http Server | 2.2.17 | All | All | All |
| Application | Apache | Http Server | 2.2.2 | All | All | All |
| Application | Apache | Http Server | 2.2.3 | All | All | All |
| Application | Apache | Http Server | 2.2.4 | All | All | All |
| Application | Apache | Http Server | 2.2.6 | All | All | All |
| Application | Apache | Http Server | 2.2.8 | All | All | All |
| Application | Apache | Http Server | 2.2.9 | All | All | All |
| Application | Apache | Http Server2.0a1 | All | All | All | All |
| Application | Apache | Http Server2.0a2 | All | All | All | All |
| Application | Apache | Http Server2.0a3 | All | All | All | All |
| Application | Apache | Http Server2.0a4 | All | All | All | All |
| Application | Apache | Http Server2.0a5 | All | All | All | All |
| Application | Apache | Http Server2.0a6 | All | All | All | All |
| Application | Apache | Http Server2.0a7 | All | All | All | All |
| Application | Apache | Http Server2.0a8 | All | All | All | All |
| Application | Apache | Http Server2.0a9 | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Debian -- Security Information -- DSA-2405-1 apache2 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Bug 752080 – CVE-2011-3639 httpd: http 0.9 request bypass of the reverse proxy vulnerability CVE-2011-3368 fix | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| [Apache-SVN] Revision 1188745 | af854a3a-2127-422b-91ae-364da2661108 | svn.apache.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.