CVE-2006-3747: High severity Apache HTTP Server vulnerability
Off-by-one error in the ldap scheme handling in the Rewrite module (modrewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2, when RewriteEngine is enabled, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted URLs that are not properly handled using certain rewrite rules.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-3747?
CVE-2006-3747 is considered to have a medium severity due to its potential to cause denial of service and possibly allow arbitrary code execution.
How do I fix CVE-2006-3747?
To fix CVE-2006-3747, upgrade your Apache HTTP Server to version 2.0.59 or later, or 2.2.0 or later.
What types of software are affected by CVE-2006-3747?
CVE-2006-3747 affects Apache HTTP Server versions 1.3.28 to 1.3.37, 2.0.46 to 2.0.59, and certain versions of Ubuntu and Debian Linux.
What is the impact of exploiting CVE-2006-3747?
Exploiting CVE-2006-3747 can lead to a denial of service attack resulting in application crashes or potentially executing arbitrary code.
Is there a workaround for CVE-2006-3747?
While upgrading is the best solution for CVE-2006-3747, disabling the RewriteEngine may serve as a temporary workaround.