CVE-2011-3192
apache2 - denial of service
EPSS 98.9%
描述
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited in the wild in August 2011, a different vulnerability than CVE-2007-0086.
如何修補 CVE-2011-3192
要修補 CVE-2011-3192,請將受影響套件升級到下列已修補版本。
- Debian/apache2—升級至 2.2.19-2 或更新版本
- Debian/apache2—升級至 2.2.9-10+lenny10 或更新版本
CVE-2011-3192 正在被利用嗎?
可能 — EPSS 為 98.9%,屬於高被利用機率區間,建議優先修補。
受影響套件(2)
- from 0, < 2.2.19-2
- from 0, < 2.2.9-10+lenny10