CVE-2011-3348: Medium severity apache http server vulnerability
modproxyajp did not correctly process certain malformed HTTP requests, which could cause it to incorrectly put a backend server to an error state until the retry timeout expired. A remote attacker could send malicious requests to trigger this issue, resulting in a temporary denial of service.
Upstream commit: http://svn.apache.org/viewvc?view=revision&revision=1166551
Reference: http://community.jboss.org/message/625307
Other sources
The modproxyajp module in the Apache HTTP Server before 2.2.21, when used with modproxybalancer in certain configurations, allows remote attackers to cause a denial of service (temporary "error state" in the backend server) via a malformed HTTP request.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3348?
CVE-2011-3348 has a medium severity level as it can lead to a temporary denial of service.
How do I fix CVE-2011-3348?
To fix CVE-2011-3348, update your affected Apache HTTP Server to version 2.2.21 or later.
Who is affected by CVE-2011-3348?
CVE-2011-3348 affects Apache HTTP Server versions between 2.2.12 and 2.2.20.
What type of attack does CVE-2011-3348 involve?
CVE-2011-3348 involves a remote attacker sending malformed HTTP requests.
What are the potential impacts of CVE-2011-3348?
The potential impact of CVE-2011-3348 is a temporary denial of service due to backend server error states.