CVE Database
/

CVE-2011-3607

Back to search

CVE-2011-3607

Published: Nov 8, 2011

Modified: Aug 6, 2024

PUBLISHED

Description

Integer overflow in the ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, allows local users to gain privileges via a .htaccess file with a crafted SetEnvIf directive, in conjunction with a crafted HTTP request header, leading to a heap-based buffer overflow.

VendorProductVersions

n/a

n/a

affected
n/a

References

HPSBMU02786
vendor-advisory
x_refsource_HP
SSRT100966
vendor-advisory
x_refsource_HP
RHSA-2012:0543
vendor-advisory
x_refsource_REDHAT
HPSBOV02822
vendor-advisory
x_refsource_HP
SSRT100772
vendor-advisory
x_refsource_HP
RHSA-2012:0128
vendor-advisory
x_refsource_REDHAT
45793
third-party-advisory
x_refsource_SECUNIA
HPSBMU02748
vendor-advisory
x_refsource_HP
50494
vdb-entry
x_refsource_BID
RHSA-2012:0542
vendor-advisory
x_refsource_REDHAT
1026267
vdb-entry
x_refsource_SECTRACK
APPLE-SA-2012-09-19-2
vendor-advisory
x_refsource_APPLE
SSRT100877
vendor-advisory
x_refsource_HP
76744
vdb-entry
x_refsource_OSVDB
HPSBUX02761
vendor-advisory
x_refsource_HP
MDVSA-2013:150
vendor-advisory
x_refsource_MANDRIVA
48551
third-party-advisory
x_refsource_SECUNIA
DSA-2405
vendor-advisory
x_refsource_DEBIAN
SSRT100823
vendor-advisory
x_refsource_HP
apache-http-appregsub-bo(71093)
vdb-entry
x_refsource_XF
MDVSA-2012:003
vendor-advisory
x_refsource_MANDRIVA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2011-3607 - Security Vulnerability | QwikSec