Apache APR 'apr_fnmatch.c' Denial of Service Vulnerability
BID:47929
Info
Apache APR 'apr_fnmatch.c' Denial of Service Vulnerability
| Bugtraq ID: | 47929 |
| Class: | Design Error |
| CVE: |
CVE-2011-1928 |
| Remote: | Yes |
| Local: | No |
| Published: | May 19 2011 12:00AM |
| Updated: | Apr 13 2015 10:01PM |
| Credit: | Apache Software Foundation |
| Vulnerable: |
Xerox FreeFlow Print Server (FFPS) 73.C0.41 Xerox FreeFlow Print Server (FFPS) 73.B3.61 Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 Ubuntu Ubuntu Linux 10.10 powerpc Ubuntu Ubuntu Linux 10.10 i386 Ubuntu Ubuntu Linux 10.10 ARM Ubuntu Ubuntu Linux 10.10 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 Sun Solaris 11 Express Sun Solaris 10_x86 Sun Solaris 10_sparc Sun Solaris 10 Express Slackware Linux x86_64 -current Slackware Linux 13.37 x86_64 Slackware Linux 13.37 Slackware Linux 13.1 x86_64 Slackware Linux 13.1 Slackware Linux 13.0 x86_64 Slackware Linux 13.0 Slackware Linux 12.2 Slackware Linux 12.1 Slackware Linux 12.0 Slackware Linux 11.0 Slackware Linux -current Redhat Enterprise Linux WS 4 Redhat Enterprise Linux Workstation 6 Redhat Enterprise Linux Server 6 Redhat Enterprise Linux HPC Node Optional 6 Redhat Enterprise Linux HPC Node 6 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux Desktop Optional 6 Redhat Enterprise Linux Desktop 6 Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux AS 4 Redhat Enterprise Linux Desktop version 4 Redhat Enterprise Linux 5 Server Mandriva Linux Mandrake 2010.1 x86_64 Mandriva Linux Mandrake 2010.1 Mandriva Linux Mandrake 2010.0 x86_64 Mandriva Linux Mandrake 2010.0 Mandriva Linux Mandrake 2009.0 x86_64 Mandriva Linux Mandrake 2009.0 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 4.0 HP System Management Homepage 6.2.2 7 HP System Management Homepage 6.0 .96 HP System Management Homepage 3.0.2 .77 HP System Management Homepage 3.0.1 .73 HP System Management Homepage 3.0 .68 HP System Management Homepage 3.0 .64 HP System Management Homepage 6.3 HP System Management Homepage 6.2.0-12 HP System Management Homepage 6.2 HP System Management Homepage 6.2 HP System Management Homepage 6.1.0.103 HP System Management Homepage 6.1.0.102 HP System Management Homepage 6.1.0-103 HP System Management Homepage 6.1 HP System Management Homepage 6.0.0.95 HP System Management Homepage 6.0.0-95 HP System Management Homepage 6.0 HP System Management Homepage 3.0.2.77 B HP System Management Homepage 3.0.2-77 HP System Management Homepage 3.0.1-73 HP System Management Homepage 3.0.0-68 HP System Management Homepage 0 HP OpenVMS Secure Web Server 2.2 Gentoo Linux Fujitsu INTERSTAGE Studio Standard-J Edition 9.2 Fujitsu INTERSTAGE Studio Standard-J Edition 9.1 Fujitsu INTERSTAGE Studio Standard-J Edition 9.0 Fujitsu INTERSTAGE Studio Standard-J Edition 8.0.1 Fujitsu INTERSTAGE Studio Standard-J Edition 9.1.0 B Fujitsu INTERSTAGE Studio Enterprise Edition 9.2 Fujitsu INTERSTAGE Studio Enterprise Edition 9.1 Fujitsu INTERSTAGE Studio Enterprise Edition 9.0 Fujitsu INTERSTAGE Studio Enterprise Edition 8.0.1 Fujitsu INTERSTAGE Studio Enterprise Edition 9.1.0 B Fujitsu INTERSTAGE Job Workload Server 8.1 Fujitsu Interstage Business Application Server Standard Edition 8.0.1 Fujitsu Interstage Business Application Server Standard Edition 8.0 Fujitsu Interstage Business Application Server Enterprise Edition 8.0.1 Fujitsu Interstage Business Application Server Enterprise Edition 8.0 Fujitsu Interstage Business Application Server Enterprise Edition 7.0.1 Fujitsu INTERSTAGE Apworks Modelers-J Edition 7.0 L10 Fujitsu INTERSTAGE Apworks Modelers-J Edition 7.0 Fujitsu INTERSTAGE Apworks Modelers-J Edition 6.0A Fujitsu INTERSTAGE Apworks Modelers-J Edition 6.0 L10A Fujitsu INTERSTAGE Apworks Modelers-J Edition 6.0 L10 Fujitsu iNTERSTAGE Application Server Web-J Edition 5.0.1 Fujitsu iNTERSTAGE Application Server Web-J Edition 5.0 L20A Fujitsu iNTERSTAGE Application Server Web-J Edition 5.0 L20 Fujitsu iNTERSTAGE Application Server Web-J Edition 5.0 L11 Fujitsu iNTERSTAGE Application Server Web-J Edition 5.0 L10B Fujitsu iNTERSTAGE Application Server Web-J Edition 5.0 L10A Fujitsu iNTERSTAGE Application Server Web-J Edition 5.0 L10 Fujitsu iNTERSTAGE Application Server Web-J Edition 5.0 Fujitsu INTERSTAGE Application Server Standard-J Edition 9.2 Fujitsu INTERSTAGE Application Server Standard-J Edition 9.1 Fujitsu INTERSTAGE Application Server Standard-J Edition 9.0.1 B Fujitsu INTERSTAGE Application Server Standard-J Edition 9.0.1 Fujitsu INTERSTAGE Application Server Standard-J Edition 9.0 B Fujitsu INTERSTAGE Application Server Standard-J Edition 9.0 A Fujitsu INTERSTAGE Application Server Standard-J Edition 9.0 Fujitsu INTERSTAGE Application Server Standard-J Edition 8.0.3 Fujitsu INTERSTAGE Application Server Standard-J Edition 8.0.2 Fujitsu INTERSTAGE Application Server Standard-J Edition 8.0.1 Fujitsu INTERSTAGE Application Server Standard-J Edition 8.0 Fujitsu INTERSTAGE Application Server Standard-J Edition 9.1.0B Fujitsu iNTERSTAGE Application Server Standard Edition 8.0.3 Fujitsu iNTERSTAGE Application Server Standard Edition 8.0 Fujitsu iNTERSTAGE Application Server Standard Edition 5.1.1 Fujitsu iNTERSTAGE Application Server Standard Edition 5.0.1 Fujitsu iNTERSTAGE Application Server Standard Edition 5.1 Fujitsu iNTERSTAGE Application Server Standard Edition 5.0 L20A Fujitsu iNTERSTAGE Application Server Standard Edition 5.0 L20 Fujitsu iNTERSTAGE Application Server Standard Edition 5.0 L11 Fujitsu iNTERSTAGE Application Server Standard Edition 5.0 L10B Fujitsu iNTERSTAGE Application Server Standard Edition 5.0 L10A Fujitsu iNTERSTAGE Application Server Standard Edition 5.0 L10 Fujitsu iNTERSTAGE Application Server Standard Edition 5.0 Fujitsu INTERSTAGE Application Server Plus Developer 5.0.1 Fujitsu INTERSTAGE Application Server Plus Developer 7.0 L10 Fujitsu INTERSTAGE Application Server Plus Developer 7.0 Fujitsu INTERSTAGE Application Server Plus Developer 6.0 L10 Fujitsu INTERSTAGE Application Server Plus Developer 6.0 Fujitsu Interstage Application Server Plus 7.0.1 Fujitsu Interstage Application Server Plus 5.0.1 Fujitsu Interstage Application Server Plus 7.0 L11 Fujitsu Interstage Application Server Plus 7.0 L10 Fujitsu Interstage Application Server Plus 7.0 Fujitsu Interstage Application Server Plus 6.0 L11 Fujitsu Interstage Application Server Plus 6.0 L10C Fujitsu Interstage Application Server Plus 6.0 L10B Fujitsu Interstage Application Server Plus 6.0 L10A Fujitsu Interstage Application Server Plus 6.0 L10 Fujitsu Interstage Application Server Plus 6.0 Fujitsu INTERSTAGE Application Server Enterprise Edition 9.2 Fujitsu INTERSTAGE Application Server Enterprise Edition 9.1 Fujitsu INTERSTAGE Application Server Enterprise Edition 9.0.1 B Fujitsu INTERSTAGE Application Server Enterprise Edition 9.0.1 Fujitsu INTERSTAGE Application Server Enterprise Edition 9.0 B Fujitsu INTERSTAGE Application Server Enterprise Edition 9.0 A Fujitsu INTERSTAGE Application Server Enterprise Edition 9.0 Fujitsu INTERSTAGE Application Server Enterprise Edition 8.0.3 Fujitsu INTERSTAGE Application Server Enterprise Edition 8.0.2 Fujitsu INTERSTAGE Application Server Enterprise Edition 8.0.1 Fujitsu INTERSTAGE Application Server Enterprise Edition 8.0 Fujitsu INTERSTAGE Application Server Enterprise Edition 7.0.1 Fujitsu INTERSTAGE Application Server Enterprise Edition 6.0.2 Fujitsu INTERSTAGE Application Server Enterprise Edition 6.0.1 Fujitsu INTERSTAGE Application Server Enterprise Edition 5.1.1 Fujitsu INTERSTAGE Application Server Enterprise Edition 5.0.1 Fujitsu INTERSTAGE Application Server Enterprise Edition 9.1.0B Fujitsu INTERSTAGE Application Server Enterprise Edition 9.1.0A Fujitsu INTERSTAGE Application Server Enterprise Edition 7.0 L11 Fujitsu INTERSTAGE Application Server Enterprise Edition 7.0 L10 Fujitsu INTERSTAGE Application Server Enterprise Edition 7.0 Fujitsu INTERSTAGE Application Server Enterprise Edition 6.0A Fujitsu INTERSTAGE Application Server Enterprise Edition 6.0 L10C Fujitsu INTERSTAGE Application Server Enterprise Edition 6.0 L10B Fujitsu INTERSTAGE Application Server Enterprise Edition 6.0 L10 Fujitsu INTERSTAGE Application Server Enterprise Edition 6.0 Fujitsu INTERSTAGE Application Server Enterprise Edition 5.1 Fujitsu INTERSTAGE Application Server Enterprise Edition 5.0 L20A Fujitsu INTERSTAGE Application Server Enterprise Edition 5.0 L20 Fujitsu INTERSTAGE Application Server Enterprise Edition 5.0 L11 Fujitsu INTERSTAGE Application Server Enterprise Edition 5.0 L10B Fujitsu INTERSTAGE Application Server Enterprise Edition 5.0 L10A Fujitsu INTERSTAGE Application Server Enterprise Edition 5.0 L10 Fujitsu INTERSTAGE Application Server Enterprise Edition 5.0 Debian Linux 5.0 sparc Debian Linux 5.0 s/390 Debian Linux 5.0 powerpc Debian Linux 5.0 mipsel Debian Linux 5.0 mips Debian Linux 5.0 m68k Debian Linux 5.0 ia-64 Debian Linux 5.0 ia-32 Debian Linux 5.0 hppa Debian Linux 5.0 armel Debian Linux 5.0 arm Debian Linux 5.0 amd64 Debian Linux 5.0 alpha Debian Linux 5.0 Avaya Voice Portal 5.1 SP1 Avaya Voice Portal 5.1 Avaya Voice Portal 5.1 Avaya Voice Portal 5.0 SP2 Avaya Voice Portal 5.0 SP1 Avaya Voice Portal 5.0 Avaya Messaging Storage Server 5.2.8 Avaya Messaging Storage Server 5.2.2 Avaya Messaging Storage Server 5.2 SP3 Avaya Messaging Storage Server 5.2 SP2 Avaya Messaging Storage Server 5.2 SP1 Avaya Messaging Storage Server 5.2 Avaya Messaging Storage Server 5.1 SP2 Avaya Messaging Storage Server 5.1 SP1 Avaya Messaging Storage Server 5.1 Avaya Messaging Storage Server 5.0 Avaya Messaging Storage Server 4.0 Avaya Message Networking 5.2.1 Avaya Message Networking 5.2.2 Avaya Message Networking 5.2 SP1 Avaya Message Networking 5.2 Avaya Message Networking 3.1 Avaya Meeting Exchange 5.2 Avaya Meeting Exchange 5.1 Avaya Meeting Exchange 5.0 Avaya IP Office Application Server 7.0 Avaya IP Office Application Server 6.1 Avaya IP Office Application Server 6.0 Avaya Interactive Response 4.0 Avaya Aura System Platform 6.0 SP3 Avaya Aura System Platform 6.0 SP2 Avaya Aura System Platform 6.0 Avaya Aura System Platform 1.0 Avaya Aura SIP Enablement Services 5.2.1 Avaya Aura SIP Enablement Services 5.2 Avaya Aura SIP Enablement Services 5.1 Avaya Aura SIP Enablement Services 5.0 Avaya Aura SIP Enablement Services 4.0 Avaya Aura Session Manager 6.1 Avaya Aura Session Manager 6.0 Avaya Aura Session Manager 5.2 Avaya Aura Session Manager 1.1 Avaya Aura Communication Manager 6.0.1 Avaya Aura Communication Manager 6.0 Avaya Aura Communication Manager 5.2 Avaya Aura Communication Manager 5.1 Avaya Aura Communication Manager 4.0 Avaya Aura Communication Manager 4.0 Avaya Aura Application Enablement Services 5.2.1 Avaya Aura Application Enablement Services 4.2.3 Avaya Aura Application Enablement Services 4.2.2 Avaya Aura Application Enablement Services 4.2.1 Avaya Aura Application Enablement Services 6.1 Avaya Aura Application Enablement Services 5.2.3 Avaya Aura Application Enablement Services 5.2.2 Avaya Aura Application Enablement Services 5.2 Avaya Aura Application Enablement Services 4.2 Apache APR-util 1.4.4 Apache APR 1.4.4 Apache Apache 2.2.18 |
| Not Vulnerable: |
HP System Management Homepage 7.0 Avaya Meeting Exchange 6.2 Avaya Aura SIP Enablement Services 5.2.1 SSP3 Avaya Aura Communication Manager 6.2 Avaya Aura Communication Manager 5.2.1 SSP3 Apache APR 1.4.5 Apache Apache 2.2.19 |
Discussion
Apache APR 'apr_fnmatch.c' Denial of Service Vulnerability
Apache APR is prone to a denial-of-service vulnerability.
NOTE: This issue is introduced in the Apache APR 1.4.4 due to an improper fix for CVE-2011-0419.
Successful exploits may allow the attacker to cause excessive CPU usage, resulting in denial-of-service conditions.
Apache APR 1.4.4 is affected.
Apache APR is prone to a denial-of-service vulnerability.
NOTE: This issue is introduced in the Apache APR 1.4.4 due to an improper fix for CVE-2011-0419.
Successful exploits may allow the attacker to cause excessive CPU usage, resulting in denial-of-service conditions.
Apache APR 1.4.4 is affected.
Exploit / POC
Apache APR 'apr_fnmatch.c' Denial of Service Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Apache APR 'apr_fnmatch.c' Denial of Service Vulnerability
Solution:
Updates are available. Please see the references for more information.
Slackware Linux 12.2
Mandriva Linux Mandrake 2009.0 x86_64
MandrakeSoft Enterprise Server 5
Slackware Linux 13.37
MandrakeSoft Corporate Server 4.0 x86_64
Solution:
Updates are available. Please see the references for more information.
Slackware Linux 12.2
-
Slackware apr-1.4.5-i486-1_slack12.2.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-12.2/patches/packages/ apr-1.4.5-i486-1_slack12.2.tgz -
Slackware apr-util-1.3.12-i486-1_slack12.2.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-12.2/patches/packages/ apr-util-1.3.12-i486-1_slack12.2.tgz
Mandriva Linux Mandrake 2009.0 x86_64
-
Mandriva lib64apr-devel-1.3.3-2.3mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva lib64apr1-1.3.3-2.3mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Enterprise Server 5
-
Mandriva libapr-devel-1.3.3-2.3mdvmes5.2.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva libapr1-1.3.3-2.3mdvmes5.2.i586.rpm
http://www.mandriva.com/en/download/
Slackware Linux 13.37
-
Slackware apr-1.4.5-i486-1_slack13.37.txz
ftp://ftp.slackware.com/pub/slackware/slackware-13.37/patches/packages /apr-1.4.5-i486-1_slack13.37.txz -
Slackware apr-util-1.3.12-i486-1_slack13.37.txz
ftp://ftp.slackware.com/pub/slackware/slackware-13.37/patches/packages /apr-util-1.3.12-i486-1_slack13.37.txz
MandrakeSoft Corporate Server 4.0 x86_64
-
Mandriva lib64apr1-1.2.7-1.3.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva lib64apr1-devel-1.2.7-1.3.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/
References
Apache APR 'apr_fnmatch.c' Denial of Service Vulnerability
References:
References:
- [Announce] Regressions in httpd 2.2.18, apr 1.4.4, and apr-util 1.3.11 (Apache Software Foundation)
- Apache APR Homepage (Apache)
- Patch (Apache Software Foundation)
- ASA-2011-197 apr security update (RHSA-2011-0844) (Avaya)
- ASA-2011-332 Multiple vulnerabilities in Apache Portable Runtime (APR) library a (Avaya)
- HPSBMU02748 SSRT100772 rev.1 - HP OpenView Network Node Manager (OV NNM) Running (HP)
- HPSBOV02822 SSRT100966 rev.1 - HP Secure Web Server (SWS) for OpenVMS, Remote De (HP)
- Interstage HTTP Server: Two Security Vulnerabilities (CVE-2011-3368/ CVE-2011-04 (Fujitsu)
- Multiple vulnerabilities in Apache Portable Runtime (APR) library and Apache HTT (Oracle)
- Xerox Security Bulletin XRX12-002 (Xerox)