Apache HTTP Server CVE-2011-3348 Denial Of Service Vulnerability
BID:49616
Info
Apache HTTP Server CVE-2011-3348 Denial Of Service Vulnerability
| Bugtraq ID: | 49616 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-3348 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 07 2011 12:00AM |
| Updated: | May 07 2015 05:12PM |
| Credit: | <br>Reported by the vendor. |
| Vulnerable: |
Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 Ubuntu Ubuntu Linux 10.10 powerpc Ubuntu Ubuntu Linux 10.10 i386 Ubuntu Ubuntu Linux 10.10 ARM Ubuntu Ubuntu Linux 10.10 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 Sun Solaris 11 Express Slackware Linux x86_64 -current Slackware Linux 13.37 x86_64 Slackware Linux 13.37 Slackware Linux 13.1 x86_64 Slackware Linux 13.1 Slackware Linux 13.0 x86_64 Slackware Linux 13.0 Slackware Linux 12.2 Slackware Linux 12.1 Slackware Linux 12.0 Slackware Linux -current Red Hat JBoss Enterprise Web Server for RHEL 6 1.0 Red Hat JBoss Enterprise Web Server for RHEL 5 Server 1.0 Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux HPC Node Optional 6 Red Hat Enterprise Linux HPC Node 6 Red Hat Enterprise Linux Desktop Optional 6 Red Hat Enterprise Linux Desktop 6 Oracle Oracle HTTP Server 9.2 .8 Oracle Oracle HTTP Server 9.2 .0 Oracle Oracle HTTP Server 9.1 Oracle Oracle HTTP Server 9.0.3 .1 Oracle Oracle HTTP Server 9.0.2 .3 Oracle Oracle HTTP Server 9.0.2 Oracle Oracle HTTP Server 9.0.1 Oracle Oracle HTTP Server 8.1.7 Oracle Oracle HTTP Server 1.0.2 .2 Roll up 2 Oracle Oracle HTTP Server 1.0.2 .2 Oracle Oracle HTTP Server 1.0.2 .1 Oracle Oracle HTTP Server 1.0.2 .0 Oracle Oracle HTTP Server 11.1.1.5 Oracle Oracle HTTP Server 11.1.1.4 Oracle Oracle HTTP Server 11.1.1.3 Oracle Oracle HTTP Server 10.1.3.5 Oracle Oracle HTTP Server 10.1.2.3 Mandriva Linux Mandrake 2010.1 x86_64 Mandriva Linux Mandrake 2010.1 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 IBM HTTP Server 7.0 .11 IBM HTTP Server 7.0.0.5 IBM HTTP Server 7.0.0.19 IBM HTTP Server 7.0.0.17 IBM HTTP Server 7.0.0.15 IBM HTTP Server 7.0.0.13 HP System Management Homepage 6.2.2 7 HP System Management Homepage 6.0 .96 HP System Management Homepage 3.0.2 .77 HP System Management Homepage 3.0.1 .73 HP System Management Homepage 3.0 .68 HP System Management Homepage 3.0 .64 HP System Management Homepage 6.3 HP System Management Homepage 6.2.0-12 HP System Management Homepage 6.2 HP System Management Homepage 6.2 HP System Management Homepage 6.1.0.103 HP System Management Homepage 6.1.0.102 HP System Management Homepage 6.1.0-103 HP System Management Homepage 6.1 HP System Management Homepage 6.0.0.95 HP System Management Homepage 6.0.0-95 HP System Management Homepage 6.0 HP System Management Homepage 3.0.2.77 B HP System Management Homepage 3.0.2-77 HP System Management Homepage 3.0.1-73 HP System Management Homepage 3.0.0-68 HP System Management Homepage 0 HP HP-UX Web Server Suite 3.18 Gentoo Linux Avaya Aura Experience Portal 6.0 Apple Mac OS X Server 10.6.6 Apple Mac OS X Server 10.6.5 Apple Mac OS X Server 10.6.4 Apple Mac OS X Server 10.6.3 Apple Mac OS X Server 10.6.2 Apple Mac OS X Server 10.6.1 Apple Mac Os X Server 10.7.2 Apple Mac Os X Server 10.7.1 Apple Mac Os X Server 10.7 Apple Mac Os X Server 10.6.8 Apple Mac Os X Server 10.6.7 Apple Mac OS X Server 10.6 Apple Mac OS X 10.6.5 Apple Mac OS X 10.6.4 Apple Mac OS X 10.6.3 Apple Mac OS X 10.6.2 Apple Mac OS X 10.6.1 Apple Mac Os X 10.7.2 Apple Mac Os X 10.7.1 Apple Mac OS X 10.6 Apache Software Foundation Apache 2.2.15 Apache Software Foundation Apache 2.2.14 Apache Software Foundation Apache 2.2.13 Apache Software Foundation Apache 2.2.12 Apache Software Foundation Apache 2.2.11 Apache Software Foundation Apache 2.2.10 Apache Software Foundation Apache 2.2.9 Apache Software Foundation Apache 2.2.8 Apache Software Foundation Apache 2.2.6 Apache Software Foundation Apache 2.2.4 Apache Software Foundation Apache 2.2.3 Apache Software Foundation Apache 2.2.2 Apache Software Foundation Apache 2.2 Apache Software Foundation Apache 2.1.9 Apache Software Foundation Apache 2.1.8 Apache Software Foundation Apache 2.1.7 Apache Software Foundation Apache 2.1.6 Apache Software Foundation Apache 2.1.5 Apache Software Foundation Apache 2.1.4 Apache Software Foundation Apache 2.1.3 Apache Software Foundation Apache 2.1.2 Apache Software Foundation Apache 2.1.1 Apache Software Foundation Apache 2.1 Apache Software Foundation Apache 2.0.63 Apache Software Foundation Apache 2.0.61 Apache Software Foundation Apache 2.0.60 Apache Software Foundation Apache 2.0.59 Apache Software Foundation Apache 2.0.58 Apache Software Foundation Apache 2.0.57 Apache Software Foundation Apache 2.0.56 Apache Software Foundation Apache 2.0.55 Apache Software Foundation Apache 2.0.54 Apache Software Foundation Apache 2.0.53 Apache Software Foundation Apache 2.0.52 Apache Software Foundation Apache 2.0.51 Apache Software Foundation Apache 2.0.50 Apache Software Foundation Apache 2.0.49 Apache Software Foundation Apache 2.0.48 Apache Software Foundation Apache 2.0.47 Apache Software Foundation Apache 2.0.46 Apache Software Foundation Apache 2.0.45 Apache Software Foundation Apache 2.0.44 Apache Software Foundation Apache 2.0.43 Apache Software Foundation Apache 2.0.42 Apache Software Foundation Apache 2.0.41 Apache Software Foundation Apache 2.0.40 Apache Software Foundation Apache 2.0.39 Apache Software Foundation Apache 2.0.38 Apache Software Foundation Apache 2.0.37 Apache Software Foundation Apache 2.0.36 Apache Software Foundation Apache 2.0.35 Apache Software Foundation Apache 2.0.34 -BETA Apache Software Foundation Apache 2.0.32 -BETA Apache Software Foundation Apache 2.0.32 Apache Software Foundation Apache 2.0.28 -BETA Apache Software Foundation Apache 2.0.28 Beta Apache Software Foundation Apache 2.0.28 Apache Software Foundation Apache 2.0.9 Apache Software Foundation Apache 2.0 Apache Software Foundation Apache 1.4 Apache Software Foundation Apache 1.3.68 Apache Software Foundation Apache 1.3.65 Apache Software Foundation Apache 1.3.42 Apache Software Foundation Apache 1.3.41 Apache Software Foundation Apache 1.3.39 Apache Software Foundation Apache 1.3.38 Apache Software Foundation Apache 1.3.37 Apache Software Foundation Apache 1.3.36 Apache Software Foundation Apache 1.3.34 Apache Software Foundation Apache 1.3.33 Apache Software Foundation Apache 1.3.32 Apache Software Foundation Apache 1.3.31 Apache Software Foundation Apache 1.3.30 Apache Software Foundation Apache 1.3.29 Apache Software Foundation Apache 1.3.28 Apache Software Foundation Apache 1.3.27 Apache Software Foundation Apache 1.3.26 Apache Software Foundation Apache 1.3.25 Apache Software Foundation Apache 1.3.24 Apache Software Foundation Apache 1.3.23 Apache Software Foundation Apache 1.3.22 Apache Software Foundation Apache 1.3.20 Apache Software Foundation Apache 1.3.19 Apache Software Foundation Apache 1.3.18 Apache Software Foundation Apache 1.3.17 Apache Software Foundation Apache 1.3.16 Apache Software Foundation Apache 1.3.15 Apache Software Foundation Apache 1.3.14 Apache Software Foundation Apache 1.3.13 Apache Software Foundation Apache 1.3.12 Apache Software Foundation Apache 1.3.11 Apache Software Foundation Apache 1.3.10 Apache Software Foundation Apache 1.3.9 Apache Software Foundation Apache 1.3.8 Apache Software Foundation Apache 1.3.7 Apache Software Foundation Apache 1.3.6 Apache Software Foundation Apache 1.3.5 Apache Software Foundation Apache 1.3.4 Apache Software Foundation Apache 1.3.3 Apache Software Foundation Apache 1.3.2 Apache Software Foundation Apache 1.3.1 Apache Software Foundation Apache 1.3 Apache Software Foundation Apache 1.2.9 Apache Software Foundation Apache 1.2.6 Apache Software Foundation Apache 1.2.5 Apache Software Foundation Apache 1.2.4 Apache Software Foundation Apache 1.2 Apache Software Foundation Apache 1.1.1 Apache Software Foundation Apache 1.1 Apache Software Foundation Apache 1.0.5 Apache Software Foundation Apache 1.0.3 Apache Software Foundation Apache 1.0.2 Apache Software Foundation Apache 1.0 Apache Software Foundation Apache 0.8.14 Apache Software Foundation Apache 0.8.11 Apache Software Foundation Apache 2.2.20 Apache Software Foundation Apache 2.2.19 Apache Software Foundation Apache 2.2.18 Apache Software Foundation Apache 2.2.17 Apache Software Foundation Apache 2.2.16 Apache Software Foundation Apache 2.2.1 Apache Software Foundation Apache 2.2 Apache Software Foundation Apache 1.99 Apache Software Foundation Apache 1.3.35 Apache Software Foundation Apache 1.3 |
| Not Vulnerable: |
IBM HTTP Server 7.0.0.21 HP System Management Homepage 7.0 Apple Mac Os X Server 10.7.3 Apple Mac Os X 10.7.3 Apache Software Foundation Apache 2.2.21 |
Discussion
Apache HTTP Server CVE-2011-3348 Denial Of Service Vulnerability
Apache HTTP Server is prone to a denial-of-service vulnerability.
Versions prior to Apache 2.2.21 are vulnerable.
Successful exploits will result in a denial-of-service condition.
Apache HTTP Server is prone to a denial-of-service vulnerability.
Versions prior to Apache 2.2.21 are vulnerable.
Successful exploits will result in a denial-of-service condition.
Exploit / POC
Apache HTTP Server CVE-2011-3348 Denial Of Service Vulnerability
An attacker can use readily available network utilities to exploit this issue.
An attacker can use readily available network utilities to exploit this issue.
Solution / Fix
Apache HTTP Server CVE-2011-3348 Denial Of Service Vulnerability
Solution:
Updates are available. Please see the references for more information.
Apple Mac Os X 10.7.2
Slackware Linux 12.2
Slackware Linux 13.1
Apple Mac Os X Server 10.7.2
Slackware Linux x86_64 -current
MandrakeSoft Enterprise Server 5
Solution:
Updates are available. Please see the references for more information.
Apple Mac Os X 10.7.2
-
Apple MacOSXUpd10.7.3.dmg
For OS X Lion v10.7.2
http://www.apple.com/support/downloads/
Slackware Linux 12.2
-
Slackware httpd-2.2.21-i486-1_slack12.2.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-12.2/patches/packages/ httpd-2.2.21-i486-1_slack12.2.tgz
Slackware Linux 13.1
-
Slackware httpd-2.2.21-i486-1_slack13.1.txz
ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/ httpd-2.2.21-i486-1_slack13.1.txz
Apple Mac Os X Server 10.7.2
-
Apple MacOSXServerUpd10.7.3.dmg
For OS X Lion Server v10.7.2
http://www.apple.com/support/downloads/
Slackware Linux x86_64 -current
-
Slackware httpd-2.2.21-x86_64-1.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/ n/httpd-2.2.21-x86_64-1.txz
MandrakeSoft Enterprise Server 5
-
Mandriva apache-base-2.2.9-12.14mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva apache-devel-2.2.9-12.14mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva apache-htcacheclean-2.2.9-12.14mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva apache-mod_authn_dbd-2.2.9-12.14mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva apache-mod_cache-2.2.9-12.14mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva apache-mod_dav-2.2.9-12.14mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva apache-mod_dbd-2.2.9-12.14mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva apache-mod_deflate-2.2.9-12.14mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva apache-mod_disk_cache-2.2.9-12.14mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva apache-mod_file_cache-2.2.9-12.14mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva apache-mod_ldap-2.2.9-12.14mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva apache-mod_mem_cache-2.2.9-12.14mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva apache-mod_proxy-2.2.9-12.14mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva apache-mod_proxy_ajp-2.2.9-12.14mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva apache-mod_ssl-2.2.9-12.14mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva apache-mod_userdir-2.2.9-12.14mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva apache-modules-2.2.9-12.14mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva apache-mpm-event-2.2.9-12.14mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva apache-mpm-itk-2.2.9-12.14mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva apache-mpm-peruser-2.2.9-12.14mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva apache-mpm-prefork-2.2.9-12.14mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva apache-mpm-worker-2.2.9-12.14mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva apache-source-2.2.9-12.14mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/
References
Apache HTTP Server CVE-2011-3348 Denial Of Service Vulnerability
References:
References:
- Apache Download Page (Apache Software Foundation)
- Fix list for IBM HTTP Server Version 7.0 (IBM)
- moderate: mod_proxy_ajp remote DoS CVE-2011-3348 (APache)
- PM47852: mod_proxy_ajp: Respond with HTTP_NOT_IMPLEMENTED when the method is not (IBM)
- [security bulletin] HPSBMU02704 SSRT100619 rev.1 - HP OpenView Network Node Man (HP)
- CVE-2011-3348 Denial of Service (DoS) vulnerability in Apache HTTP Server (Oracle)
- httpd security and bug fix update (RHSA-2011-1391) (Avaya Inc.)
- Oracle Critical Patch Update Advisory - July 2013 (Oracle)