CVE-2011-3348: Medium severity apache http server vulnerability

Published Sep 8, 2011
·
Updated

modproxyajp did not correctly process certain malformed HTTP requests, which could cause it to incorrectly put a backend server to an error state until the retry timeout expired. A remote attacker could send malicious requests to trigger this issue, resulting in a temporary denial of service.

Upstream commit: http://svn.apache.org/viewvc?view=revision&revision=1166551

Reference: http://community.jboss.org/message/625307

Other sources

The modproxyajp module in the Apache HTTP Server before 2.2.21, when used with modproxybalancer in certain configurations, allows remote attackers to cause a denial of service (temporary "error state" in the backend server) via a malformed HTTP request.

MITRE

Affected Software

5 affected componentsFixes available
redhat/httpd<2.2.21
2.2.21
Apache HTTP Server>=2.2.12<=2.2.20
redhat Jboss Enterprise Web Server=1.0.0
redhat Enterprise Linux=6.0
redhat Enterprise Linux=7.0

Event History

Sep 19, 2011
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2011-3348?

CVE-2011-3348 has a medium severity level as it can lead to a temporary denial of service.

2

How do I fix CVE-2011-3348?

To fix CVE-2011-3348, update your affected Apache HTTP Server to version 2.2.21 or later.

3

Who is affected by CVE-2011-3348?

CVE-2011-3348 affects Apache HTTP Server versions between 2.2.12 and 2.2.20.

4

What type of attack does CVE-2011-3348 involve?

CVE-2011-3348 involves a remote attacker sending malformed HTTP requests.

5

What are the potential impacts of CVE-2011-3348?

The potential impact of CVE-2011-3348 is a temporary denial of service due to backend server error states.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203