CVE-2011-3192: High severity apache http server vulnerability
An exploit was posted to full-disclosure labelled "Apache Killer". This script creates a number of threads that use multiple Range headers to exhaust memory on the Apache server.
The ASF httpd development team are working on a fix for this issue: http://www.gossamer-threads.com/lists/apache/dev/401638
Other sources
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited in the wild in August 2011, a different vulnerability than CVE-2007-0086.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3192?
CVE-2011-3192 is considered a high severity vulnerability that could lead to denial of service on Apache servers.
How do I fix CVE-2011-3192?
To fix CVE-2011-3192, you should upgrade your Apache server to version 2.2.21 or later.
Which software versions are affected by CVE-2011-3192?
CVE-2011-3192 affects Apache HTTP Server versions before 2.2.21 and certain specific versions of SUSE and Ubuntu distributions.
What impact does CVE-2011-3192 have on Apache servers?
The impact of CVE-2011-3192 is that it can exhaust memory resources on Apache servers through crafted HTTP requests.
Is there a patch available for CVE-2011-3192?
Yes, the Apache Software Foundation has released updates that patch CVE-2011-3192.