CVE-2011-0419

Severity

43%

Complexity

86%

Confidentiality

48%

Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac OS X 10.6, Oracle Solaris 10, and Android, allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via *? sequences in the first argument, as demonstrated by attacks against mod_autoindex in httpd.

Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac OS X 10.6, Oracle Solaris 10, and Android, allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via *? sequences in the first argument, as demonstrated by attacks against mod_autoindex in httpd.

CVSS 2.0 Base Score 4.3. CVSS Attack Vector: network. CVSS Attack Complexity: medium. CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:P).

Overview

First reported 13 years ago

2011-05-16 17:55:00

Last updated 7 years ago

2018-01-06 02:29:00

Affected Software

Apache Software Foundation Apache HTTP Server 0.8.11

0.8.11

Apache Software Foundation Apache HTTP Server 0.8.14

0.8.14

Apache Software Foundation Apache HTTP Server 1.0

1.0

Apache Software Foundation Apache HTTP Server 1.0.2

1.0.2

Apache Software Foundation Apache HTTP Server 1.0.3

1.0.3

Apache Software Foundation Apache HTTP Server 1.0.5

1.0.5

Apache Software Foundation Apache HTTP Server 1.1

1.1

Apache Software Foundation Apache HTTP Server 1.1.1

1.1.1

Apache Software Foundation Apache 1.2

1.2

Apache Software Foundation Apache HTTP Server 1.2.4

1.2.4

Apache Software Foundation Apache HTTP Server 1.2.5

1.2.5

Apache Software Foundation Apache HTTP Server 1.2.6

1.2.6

Apache Software Foundation Apache 1.29

1.2.9

Apache Software Foundation Apache HTTP Server 1.3

1.3

Apache Software Foundation Apache HTTP Server 1.3.0

1.3.0

Apache Software Foundation Apache HTTP Server 1.3.1

1.3.1

Apache Software Foundation Apache HTTP Server 1.3.1.1

1.3.1.1

Apache Software Foundation Apache HTTP Server 1.3.2

1.3.2

Apache Software Foundation Apache HTTP Server 1.3.3

1.3.3

Apache Software Foundation Apache HTTP Server 1.3.4

1.3.4

Apache Software Foundation Apache HTTP Server 1.3.5

1.3.5

Apache Software Foundation Apache HTTP Server 1.3.6

1.3.6

Apache Software Foundation Apache HTTP Server 1.3.7

1.3.7

Apache Software Foundation Apache HTTP Server 1.3.8

1.3.8

Apache Software Foundation Apache HTTP Server 1.3.9

1.3.9

Apache Software Foundation Apache 1.3.10

1.3.10

Apache Software Foundation Apache HTTP Server 1.3.11

1.3.11

Apache Software Foundation Apache HTTP Server 1.3.12

1.3.12

Apache Software Foundation Apache 1.3.13

1.3.13

Apache Software Foundation Apache HTTP Server 1.3.14

1.3.14

Apache Software Foundation Apache 1.3.15

1.3.15

Apache Software Foundation Apache 1.3.16

1.3.16

Apache Software Foundation Apache HTTP Server 1.3.17

1.3.17

Apache Software Foundation Apache HTTP Server 1.3.18

1.3.18

Apache Software Foundation Apache HTTP Server 1.3.19

1.3.19

Apache Software Foundation Apache HTTP Server 1.3.20

1.3.20

Apache Software Foundation Apache HTTP Server 1.3.22

1.3.22

Apache Software Foundation Apache HTTP Server 1.3.23

1.3.23

Apache Software Foundation Apache HTTP Server 1.3.24

1.3.24

Apache Software Foundation Apache HTTP Server 1.3.25

1.3.25

Apache Software Foundation Apache HTTP Server 1.3.26

1.3.26

Apache Software Foundation Apache HTTP Server 1.3.27

1.3.27

Apache Software Foundation Apache HTTP Server 1.3.28

1.3.28

Apache Software Foundation Apache HTTP Server 1.3.29

1.3.29

Apache Software Foundation Apache HTTP Server 1.3.30

1.3.30

Apache Software Foundation Apache HTTP Server 1.3.31

1.3.31

Apache Software Foundation Apache HTTP Server 1.3.32

1.3.32

Apache Software Foundation Apache HTTP Server 1.3.33

1.3.33

Apache Software Foundation Apache HTTP Server 1.3.34

1.3.34

Apache Software Foundation Apache HTTP Server 1.3.35

1.3.35

Apache Software Foundation Apache HTTP Server 1.3.36

1.3.36

Apache Software Foundation Apache HTTP Server 1.3.37

1.3.37

Apache Software Foundation Apache HTTP Server 1.3.38

1.3.38

Apache Software Foundation Apache HTTP Server 1.3.39

1.3.39

Apache Software Foundation Apache HTTP Server 1.3.41

1.3.41

Apache Software Foundation Apache HTTP Server 1.3.42

1.3.42

Apache Software Foundation Apache HTTP Server 1.3.65

1.3.65

Apache Software Foundation Apache HTTP Server 1.3.68

1.3.68

Apache Software Foundation Apache HTTP Server 1.4.0

1.4.0

Apache Software Foundation Apache HTTP Server 1.99

1.99

Apache Software Foundation Apache HTTP Server 2.0

2.0

Apache Software Foundation Apache HTTP Server 2.0.9a

2.0.9

Apache Software Foundation Apache HTTP Server 2.0.28

2.0.28

Apache Software Foundation Apache HTTP Server 2.0.28 Beta

2.0.28

Apache Software Foundation Apache HTTP Server 2.0.32

2.0.32

Apache Software Foundation Apache HTTP Server 2.0.32 Beta

2.0.32

Apache Software Foundation Apache HTTP Server 2.0.34 Beta

2.0.34

Apache Software Foundation Apache HTTP Server 2.0.35

2.0.35

Apache Software Foundation Apache HTTP Server 2.0.36

2.0.36

Apache Software Foundation Apache HTTP Server 2.0.37

2.0.37

Apache Software Foundation Apache HTTP Server 2.0.38

2.0.38

Apache Software Foundation Apache HTTP Server 2.0.39

2.0.39

Apache Software Foundation Apache HTTP Server 2.0.40

2.0.40

Apache Software Foundation Apache HTTP Server 2.0.41

2.0.41

Apache Software Foundation Apache HTTP Server 2.0.42

2.0.42

Apache Software Foundation Apache HTTP Server 2.0.43

2.0.43

Apache Software Foundation Apache HTTP Server 2.0.44

2.0.44

Apache Software Foundation Apache HTTP Server 2.0.45

2.0.45

Apache Software Foundation Apache HTTP Server 2.0.46

2.0.46

Apache Software Foundation Apache HTTP Server 2.0.47

2.0.47

Apache Software Foundation Apache HTTP Server 2.0.48

2.0.48

Apache Software Foundation Apache HTTP Server 2.0.49

2.0.49

Apache Software Foundation Apache HTTP Server 2.0.50

2.0.50

Apache Software Foundation Apache HTTP Server 2.0.51

2.0.51

Apache Software Foundation Apache HTTP Server 2.0.52

2.0.52

Apache Software Foundation Apache HTTP Server 2.0.53

2.0.53

Apache Software Foundation Apache HTTP Server 2.0.54

2.0.54

Apache Software Foundation Apache HTTP Server 2.0.55

2.0.55

Apache Software Foundation Apache HTTP Server 2.0.56

2.0.56

Apache Software Foundation Apache HTTP Server 2.0.57

2.0.57

Apache Software Foundation Apache HTTP Server 2.0.58

2.0.58

Apache Software Foundation HTTP Server 2.0.59

2.0.59

Apache Software Foundation Apache HTTP Server 2.0.60 dev

2.0.60

Apache Software Foundation HTTP Server 2.0.61

2.0.61

Apache Software Foundation Apache HTTP Server 2.0.63

2.0.63

Apache Software Foundation Apache HTTP Server 2.1

2.1

Apache Software Foundation Apache HTTP Server 2.1.1

2.1.1

Apache Software Foundation Apache HTTP Server 2.1.2

2.1.2

Apache Software Foundation Apache HTTP Server 2.1.3

2.1.3

Apache Software Foundation Apache HTTP Server 2.1.4

2.1.4

Apache Software Foundation Apache HTTP Server 2.1.5

2.1.5

Apache Software Foundation Apache HTTP Server 2.1.6

2.1.6

Apache Software Foundation Apache HTTP Server 2.1.7

2.1.7

Apache Software Foundation Apache HTTP Server 2.1.8

2.1.8

Apache Software Foundation Apache HTTP Server 2.1.9

2.1.9

Apache Software Foundation Apache HTTP Server 2.2

2.2

Apache Software Foundation Apache HTTP Server 2.2.0

2.2.0

Apache Software Foundation Apache HTTP Server 2.2.1

2.2.1

Apache Software Foundation Apache HTTP Server 2.2.2

2.2.2

Apache Software Foundation Apache HTTP Server 2.2.3

2.2.3

Apache Software Foundation Apache HTTP Server 2.2.4

2.2.4

Apache Software Foundation Apache HTTP Server 2.2.6

2.2.6

Apache Software Foundation Apache HTTP Server 2.2.8

2.2.8

Apache Software Foundation Apache HTTP Server 2.2.9

2.2.9

Apache Software Foundation Apache HTTP Server 2.2.10

2.2.10

Apache Software Foundation Apache HTTP Server 2.2.11

2.2.11

Apache Software Foundation Apache HTTP Server 2.2.12

2.2.12

Apache Software Foundation Apache HTTP Server 2.2.13

2.2.13

Apache Software Foundation Apache HTTP Server 2.2.14

2.2.14

Apache Software Foundation Apache HTTP Server 2.2.15

2.2.15

Apache Software Foundation Apache HTTP Server 2.2.16

2.2.16

Apache Software Foundation Apache HTTP Server

Apple Mac OS X 10.6.0

10.6.0

FreeBSD

Google Android Operating System

NetBSD 5.1

5.1

OpenBSD 4.8

4.8

Oracle Solaris 10

10

References

http://cvsweb.netbsd.org/bsdweb.cgi/src/lib/libc/gen/fnmatch.c#rev1.22

http://cxib.net/stuff/apache.fnmatch.phps

Patch

http://cxib.net/stuff/apr_fnmatch.txts

http://httpd.apache.org/security/vulnerabilities_22.html

Vendor Advisory

APPLE-SA-2011-10-12-3

SUSE-SU-2011:1229

HPSBUX02702

HPSBUX02707

SSRT100619

SSRT100966

44490

Vendor Advisory

44564

Vendor Advisory

44574

Vendor Advisory

48308

20110512 Multiple Vendors libc/fnmatch(3) DoS (incl apache)

8246

1025527

http://support.apple.com/kb/HT5002

http://svn.apache.org/viewvc/apr/apr/branches/1.4.x/strings/apr_fnmatch.c?r1=731029&r2=1098902

Patch

http://svn.apache.org/viewvc?view=revision&revision=1098188

Patch

http://svn.apache.org/viewvc?view=revision&revision=1098799

Patch

http://www.apache.org/dist/apr/Announcement1.x.html

Patch

http://www.apache.org/dist/apr/CHANGES-APR-1.4

http://www.apache.org/dist/httpd/Announcement2.2.html

Patch

DSA-2237

[dev] 20110510 Re: fnmatch rewrite in apr, apr 1.4.3

[dev] 20110510 Re: Apache Portable Runtime 1.4.4 [...] Released

[dev] 20110511 Re: Apache Portable Runtime 1.4.4 [...] Released

MDVSA-2011:084

MDVSA-2013:150

http://www.openbsd.org/cgi-bin/cvsweb/src/lib/libc/gen/fnmatch.c#rev1.15

http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.html

http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html

RHSA-2011:0507

RHSA-2011:0896

RHSA-2011:0897

https://bugzilla.redhat.com/show_bug.cgi?id=703390

Patch

[httpd-cvs] 20190815 svn commit: r1048742 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html

[httpd-cvs] 20190815 svn commit: r1048743 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html

[httpd-cvs] 20190815 svn commit: r1048743 [3/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html

[httpd-cvs] 20190815 svn commit: r1048742 [3/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html

[httpd-cvs] 20200401 svn commit: r1058586 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html

[httpd-cvs] 20200401 svn commit: r1058586 [3/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html

[httpd-cvs] 20200401 svn commit: r1058587 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html

[httpd-cvs] 20200401 svn commit: r1058587 [3/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html

oval:org.mitre.oval:def:14638

oval:org.mitre.oval:def:14804

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.