ID

VAR-201108-0132


CVE

CVE-2011-3192


TITLE

Apache HTTPD 1.3/2.x Range header DoS vulnerability

Trust: 0.8

sources: CERT/CC: VU#405811

DESCRIPTION

The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited in the wild in August 2011, a different vulnerability than CVE-2007-0086. Both the 'Range' header and the 'Range-Request' header are vulnerable. The attack tool causes a significant increase in CPU and memory usage on the server. Apache HTTPD The server has a service disruption (DoS) Vulnerabilities exist. Apache HTTPD The server Range Header and Request-Range There is a problem with header processing, and service operation is interrupted. (DoS) Vulnerabilities exist. Attacks using this vulnerability have been observed. Also, "Apache Killer" The attack tool called is released. Apache The advisory states that: "Background and the 2007 report There are two aspects to this vulnerability. One is new, is Apache specific; and resolved with this server side fix. The other issue is fundamentally a protocol design issue dating back to 2007: http://seclists.org/bugtraq/2007/Jan/83 The contemporary interpretation of the HTTP protocol (currently) requires a server to return multiple (overlapping) ranges; in the order requested. This means that one can request a very large range (e.g. from byte 0- to the end) 100's of times in a single request. Being able to do so is an issue for (probably all) webservers and currently subject of an IETF discussion to change the protocol: http://trac.tools.ietf.org/wg/httpbis/trac/ticket/311 This advisory details a problem with how Apache httpd and its so called internal 'bucket brigades' deal with serving such "valid" request. The problem is that currently such requests internally explode into 100's of large fetches, all of which are kept in memory in an inefficient way. This is being addressed in two ways. By making things more efficient. And by weeding out or simplifying requests deemed too unwieldy."Service disruption by a remote third party (DoS) There is a possibility of being attacked. ---------------------------------------------------------------------- The Secunia CSI 5.0 Beta - now available for testing Find out more, take a free test drive, and share your opinion with us: http://secunia.com/blog/242 ---------------------------------------------------------------------- TITLE: Hitachi Web Server ByteRange Filter Denial of Service Vulnerability SECUNIA ADVISORY ID: SA45865 VERIFY ADVISORY: Secunia.com http://secunia.com/advisories/45865/ Customer Area (Credentials Required) https://ca.secunia.com/?page=viewadvisory&vuln_id=45865 RELEASE DATE: 2011-09-05 DISCUSS ADVISORY: http://secunia.com/advisories/45865/#comments AVAILABLE ON SITE AND IN CUSTOMER AREA: * Last Update * Popularity * Comments * Criticality Level * Impact * Where * Solution Status * Operating System / Software * CVE Reference(s) http://secunia.com/advisories/45865/ ONLY AVAILABLE IN CUSTOMER AREA: * Authentication Level * Report Reliability * Secunia PoC * Secunia Analysis * Systems Affected * Approve Distribution * Remediation Status * Secunia CVSS Score * CVSS https://ca.secunia.com/?page=viewadvisory&vuln_id=45865 ONLY AVAILABLE WITH SECUNIA CSI AND SECUNIA PSI: * AUTOMATED SCANNING http://secunia.com/vulnerability_scanning/personal/ http://secunia.com/vulnerability_scanning/corporate/wsus_sccm_3rd_third_party_patching/ DESCRIPTION: Hitachi has acknowledged a vulnerability in Hitachi Web Server, which can be exploited by malicious people to cause a DoS (Denial of Service). SOLUTION: Apply a workaround (please see the vendor's advisory for details). ORIGINAL ADVISORY: Hitachi (Japanese): http://www.hitachi.co.jp/Prod/comp/soft1/security/info/./vuls/HS11-019/index.html OTHER REFERENCES: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ DEEP LINKS: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXTENDED DESCRIPTION: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXTENDED SOLUTION: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXPLOIT: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help private users keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/advisories/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ---------------------------------------------------------------------- . Summary: Updated httpd packages that fix one security issue are now available for Red Hat Application Stack v2. The Red Hat Security Response Team has rated this update as having important security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: Red Hat Application Stack v2 for Enterprise Linux (v.5) - i386, x86_64 3. (CVE-2011-3192) All httpd users should upgrade to these updated packages, which contain a backported patch to correct this issue. After installing the updated packages, the httpd daemon must be restarted for the update to take effect. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/kb/docs/DOC-11259 5. Bugs fixed (http://bugzilla.redhat.com/): 732928 - CVE-2011-3192 httpd: multiple ranges DoS 6. Package List: Red Hat Application Stack v2 for Enterprise Linux (v.5): Source: ftp://ftp.redhat.com/pub/redhat/linux/enterprise/5Server/en/RHWAS/SRPMS/httpd-2.2.13-3.el5s2.src.rpm i386: httpd-2.2.13-3.el5s2.i386.rpm httpd-debuginfo-2.2.13-3.el5s2.i386.rpm httpd-devel-2.2.13-3.el5s2.i386.rpm httpd-manual-2.2.13-3.el5s2.i386.rpm mod_ssl-2.2.13-3.el5s2.i386.rpm x86_64: httpd-2.2.13-3.el5s2.x86_64.rpm httpd-debuginfo-2.2.13-3.el5s2.i386.rpm httpd-debuginfo-2.2.13-3.el5s2.x86_64.rpm httpd-devel-2.2.13-3.el5s2.i386.rpm httpd-devel-2.2.13-3.el5s2.x86_64.rpm httpd-manual-2.2.13-3.el5s2.x86_64.rpm mod_ssl-2.2.13-3.el5s2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/#package 7. References: https://www.redhat.com/security/data/cve/CVE-2011-3192.html https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2011 Red Hat, Inc. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c03025215 Version: 1 HPSBUX02707 SSRT100626 rev.1 - HP-UX Apache Web Server, Remote Denial of Service (DoS) NOTICE: The information in this Security Bulletin should be acted upon as soon as possible. Release Date: 2011-09-26 Last Updated: 2011-09-26 ------------------------------------------------------------------------------ Potential Security Impact: Remote Denial of Service (DoS) Source: Hewlett-Packard Company, HP Software Security Response Team VULNERABILITY SUMMARY A potential security vulnerability has been identified with HP-UX Apache Web Server. This vulnerability could be exploited remotely to create a Denial of Service (DoS). References: CVE-2011-0419, CVE-2011-3192, CVE-2011-3348 SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed. HP-UX B.11.23, B.11.31 running HP-UX Apache Web Server Suite v3.18 containing Apache v2.2.15.08 or earlier BACKGROUND CVSS 2.0 Base Metrics =========================================================== Reference Base Vector Base Score CVE-2011-0419 (AV:N/AC:M/Au:N/C:N/I:N/A:P) 4.3 CVE-2011-3192 (AV:N/AC:L/Au:N/C:N/I:N/A:C) 7.8 CVE-2011-3348 (AV:N/AC:M/Au:N/C:N/I:N/A:P) 4.3 =========================================================== Information on CVSS is documented in HP Customer Notice: HPSN-2008-002 RESOLUTION This bulletin will be revised when additional information becomes available. HP has provided the following preliminary software updates to resolve this vulnerability. The updates are available for download from the following location ftp://srt10626:Secure12@ftp.usa.hp.com/ or via HTTPS Access: https://ftp.usa.hp.com/hprc with username srt10626 and password Secure12 HP-UX Web Server Suite (WSS) v3.18 containing Apache v2.2.15.08.01 HP-UX 11i Releases / Apache Depot name B.11.23 B.11.31 (32-bit) / IA-PA-32.depot B.11.23 B.11.31 (64-bit) / IA-PA-64.depot NOTE: HP-UX Web Server Suite (WSS) v2.33 is not affected by this. MANUAL ACTIONS: Yes - Update Install HP-UX Web Server Suite v3.18 containing v2.2.15.08.01 or subsequent. PRODUCT SPECIFIC INFORMATION HP-UX Software Assistant: HP-UX Software Assistant is an enhanced application that replaces HP-UX Security Patch Check. It analyzes all Security Bulletins issued by HP and lists recommended actions that may apply to a specific HP-UX system. It can also download patches and create a depot automatically. For more information see https://www.hp.com/go/swa The following text is for use by the HP-UX Software Assistant. AFFECTED VERSIONS HP-UX Web Server Suite v3.18 HP-UX B.11.23 HP-UX B.11.31 ================== hpuxws22APCH32.APACHE hpuxws22APCH32.APACHE2 hpuxws22APCH32.AUTH_LDAP hpuxws22APCH32.AUTH_LDAP2 hpuxws22APCH32.MOD_JK hpuxws22APCH32.MOD_JK2 hpuxws22APCH32.MOD_PERL hpuxws22APCH32.MOD_PERL2 hpuxws22APCH32.PHP hpuxws22APCH32.PHP2 hpuxws22APCH32.WEBPROXY hpuxws22APCH32.WEBPROXY2 hpuxws22APACHE.APACHE hpuxws22APACHE.APACHE2 hpuxws22APACHE.AUTH_LDAP hpuxws22APACHE.AUTH_LDAP2 hpuxws22APACHE.MOD_JK hpuxws22APACHE.MOD_JK2 hpuxws22APACHE.MOD_PERL hpuxws22APACHE.MOD_PERL2 hpuxws22APACHE.PHP hpuxws22APACHE.PHP2 hpuxws22APACHE.WEBPROXY hpuxws22APACHE.WEBPROXY2 action: install revision B.2.2.15.08.01 or subsequent END AFFECTED VERSIONS HISTORY Version:1 (rev.1) - 26 September 2011 Initial release Third Party Security Patches: Third party security patches that are to be installed on systems running HP software products should be applied in accordance with the customer's patch management policy. Support: For further information, contact normal HP Services support channel. Report: To report a potential security vulnerability with any HP supported product, send Email to: security-alert@hp.com Subscribe: To initiate a subscription to receive future HP Security Bulletin alerts via Email: http://h41183.www4.hp.com/signup_alerts.php?jumpid=hpsc_secbulletins Security Bulletin List: A list of HP Security Bulletins, updated periodically, is contained in HP Security Notice HPSN-2011-001: https://h20566.www2.hp.com/portal/site/hpsc/public/kb/docDisplay/?docId=emr_na-c02964430 3C = 3COM 3P = 3rd Party Software GN = HP General Software HF = HP Hardware and Firmware MP = MPE/iX MU = Multi-Platform Software NS = NonStop Servers OV = OpenVMS PI = Printing and Imaging PV = ProCurve ST = Storage Software TU = Tru64 UNIX UX = HP-UX Copyright 2011 Hewlett-Packard Development Company, L.P. Hewlett-Packard Company shall not be liable for technical or editorial errors or omissions contained herein. The information provided is provided "as is" without warranty of any kind. To the extent permitted by law, neither HP or its affiliates, subcontractors or suppliers will be liable for incidental,special or consequential damages including downtime cost; lost profits;damages relating to the procurement of substitute products or services; or damages for loss of data, or software restoration. The information in this document is subject to change without notice. Hewlett-Packard Company and the names of Hewlett-Packard products referenced herein are trademarks of Hewlett-Packard Company in the United States and other countries. Other product and company names mentioned herein may be trademarks of their respective owners. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iEYEARECAAYFAk6BBLEACgkQ4B86/C0qfVm4CACfVi1NP6JFycNeJ1OZHPsIyXB1 d1oAn1bBizdn88C0MvGNNoc8KZ9ZydIV =q33p -----END PGP SIGNATURE----- . HP System Management Homepage (SMH) before v7.0 running on Linux and Windows. For other issues about the content of this Security Bulletin, send e-mail to security-alert@hp.com. This issue only affects the Debian 5.0 oldstable/lenny distribution. For the oldstable distribution (lenny), these problems have been fixed in version 2.2.9-10+lenny10. For the stable distribution (squeeze), this problem has been fixed in version 2.2.16-6+squeeze2. For the testing distribution (wheezy), this problem will be fixed soon. For the unstable distribution (sid), this problem has been fixed in version 2.2.19-2. We recommend that you upgrade your apache2 packages. The new version number for the oldstable distribution is 2.2.6-02-1+lenny5. In the stable distribution, apache2-mpm-itk has the same version number as apache2. HP Secure Web Server (SWS) for OpenVMS V2.2 and earlier

Trust: 2.97

sources: NVD: CVE-2011-3192 // CERT/CC: VU#405811 // JVNDB: JVNDB-2011-002172 // VULMON: CVE-2011-3192 // PACKETSTORM: 104804 // PACKETSTORM: 105792 // PACKETSTORM: 105422 // PACKETSTORM: 112043 // PACKETSTORM: 104587 // PACKETSTORM: 117251

AFFECTED PRODUCTS

vendor:susemodel:linux enterprise software development kitscope:eqversion:11

Trust: 1.0

vendor:canonicalmodel:ubuntu linuxscope:eqversion:10.04

Trust: 1.0

vendor:apachemodel:http serverscope:ltversion:2.0.65

Trust: 1.0

vendor:apachemodel:http serverscope:gteversion:2.2.0

Trust: 1.0

vendor:susemodel:linux enterprise serverscope:eqversion:11

Trust: 1.0

vendor:apachemodel:http serverscope:gteversion:2.0.35

Trust: 1.0

vendor:apachemodel:http serverscope:ltversion:2.2.20

Trust: 1.0

vendor:susemodel:linux enterprise software development kitscope:eqversion:10

Trust: 1.0

vendor:opensusemodel:opensusescope:eqversion:11.3

Trust: 1.0

vendor:canonicalmodel:ubuntu linuxscope:eqversion:8.04

Trust: 1.0

vendor:opensusemodel:opensusescope:eqversion:11.4

Trust: 1.0

vendor:susemodel:linux enterprise serverscope:eqversion:10

Trust: 1.0

vendor:canonicalmodel:ubuntu linuxscope:eqversion:11.04

Trust: 1.0

vendor:canonicalmodel:ubuntu linuxscope:eqversion:10.10

Trust: 1.0

vendor:apache http servermodel: - scope: - version: -

Trust: 0.8

vendor:ciscomodel: - scope: - version: -

Trust: 0.8

vendor:debian gnu linuxmodel: - scope: - version: -

Trust: 0.8

vendor:mandriva s amodel: - scope: - version: -

Trust: 0.8

vendor:oraclemodel: - scope: - version: -

Trust: 0.8

vendor:apachemodel:http serverscope:eqversion:1.3 system

Trust: 0.8

vendor:apachemodel:http serverscope:eqversion:2.x system

Trust: 0.8

vendor:ibmmodel:http serverscope:eqversion:1.3

Trust: 0.8

vendor:ibmmodel:http serverscope:eqversion:2.0

Trust: 0.8

vendor:ibmmodel:http serverscope:eqversion:6.0

Trust: 0.8

vendor:ibmmodel:http serverscope:eqversion:6.1

Trust: 0.8

vendor:ibmmodel:http serverscope:eqversion:7.0

Trust: 0.8

vendor:ibmmodel:http serverscope:eqversion:8.0

Trust: 0.8

vendor:applemodel:mac os xscope:eqversion:v10.6.8

Trust: 0.8

vendor:applemodel:mac os xscope:eqversion:v10.7 and v10.7.1

Trust: 0.8

vendor:applemodel:mac os x serverscope:eqversion:v10.6.8

Trust: 0.8

vendor:applemodel:mac os x serverscope:eqversion:v10.7 and v10.7.1

Trust: 0.8

vendor:oraclemodel:application serverscope:eqversion:10g release 2 version 10.1.2.3

Trust: 0.8

vendor:oraclemodel:application serverscope:eqversion:10g release 3 version 10.1.3.5

Trust: 0.8

vendor:oraclemodel:fusion middlewarescope:eqversion:11g release 1 11.1.1.3

Trust: 0.8

vendor:oraclemodel:fusion middlewarescope:eqversion:11g release 1 11.1.1.4

Trust: 0.8

vendor:oraclemodel:fusion middlewarescope:eqversion:11g release 1 11.1.1.5

Trust: 0.8

vendor:oraclemodel:secure backupscope:eqversion:10.3.0.3

Trust: 0.8

vendor:oraclemodel:secure backupscope:eqversion:10.4.0.1

Trust: 0.8

vendor:oraclemodel:solarisscope:eqversion:10

Trust: 0.8

vendor:oraclemodel:solarisscope:eqversion:11 express

Trust: 0.8

vendor:oraclemodel:supply chain products suitescope:eqversion:5.5.06

Trust: 0.8

vendor:oraclemodel:supply chain products suitescope:eqversion:6.0

Trust: 0.8

vendor:oraclemodel:supply chain products suitescope:eqversion:6.1

Trust: 0.8

vendor:oraclemodel:supply chain products suitescope:eqversion:6.2

Trust: 0.8

vendor:cybertrustmodel:asianux serverscope:eqversion:3.0

Trust: 0.8

vendor:cybertrustmodel:asianux serverscope:eqversion:3.0 (x86-64)

Trust: 0.8

vendor:cybertrustmodel:asianux serverscope:eqversion:4.0

Trust: 0.8

vendor:cybertrustmodel:asianux serverscope:eqversion:4.0 (x86-64)

Trust: 0.8

vendor:hewlett packardmodel:hp secure web server for openvmsscope:lteversion:v2.2

Trust: 0.8

vendor:hewlett packardmodel:hp-uxscope:eqversion:11.23

Trust: 0.8

vendor:hewlett packardmodel:hp-uxscope:eqversion:11.31

Trust: 0.8

vendor:hewlett packardmodel:hp-ux web server suitescope:eqversion:v3.19

Trust: 0.8

vendor:ricohmodel:ridoc document routerscope:ltversion:pro v2 v.2.2.5.0

Trust: 0.8

vendor:ricohmodel:ridoc document routerscope:ltversion:v3 v.3.2.5.0

Trust: 0.8

vendor:ricohmodel:ridoc document routerscope:ltversion:v4 v.4.0.6.0

Trust: 0.8

vendor:ricohmodel:ridoc document serverscope:ltversion:ep v1 / v1 type h v.1.0.6.0

Trust: 0.8

vendor:ricohmodel:ridoc document serverscope:ltversion:ep v2 / v2 type h v.2.0.5.0

Trust: 0.8

vendor:ricohmodel:ridoc document serverscope:ltversion:v3 v.3.2.4.0

Trust: 0.8

vendor:ricohmodel:ridoc document systemscope:ltversion:image log options v1 v.1.1.5.0

Trust: 0.8

vendor:ricohmodel:ridoc io operationserverscope:ltversion:pro / device operation management utility is02.09.00

Trust: 0.8

vendor:ricohmodel:ridoc web navigatorscope:ltversion:lt v.1.0.6.0

Trust: 0.8

vendor:ricohmodel:ridoc web navigatorscope:ltversion:v3 v.3.3.8.0

Trust: 0.8

vendor:red hatmodel:enterprise linuxscope:eqversion:4 (as)

Trust: 0.8

vendor:red hatmodel:enterprise linuxscope:eqversion:4 (es)

Trust: 0.8

vendor:red hatmodel:enterprise linuxscope:eqversion:4 (ws)

Trust: 0.8

vendor:red hatmodel:enterprise linuxscope:eqversion:5 (server)

Trust: 0.8

vendor:red hatmodel:enterprise linux desktopscope:eqversion:4.0

Trust: 0.8

vendor:red hatmodel:enterprise linux desktopscope:eqversion:5.0 (client)

Trust: 0.8

vendor:red hatmodel:enterprise linux desktopscope:eqversion:6

Trust: 0.8

vendor:red hatmodel:enterprise linux elsscope:eqversion:3

Trust: 0.8

vendor:red hatmodel:enterprise linux eusscope:eqversion:5.6.z (server)

Trust: 0.8

vendor:red hatmodel:enterprise linux hpc nodescope:eqversion:6

Trust: 0.8

vendor:red hatmodel:enterprise linux long lifescope:eqversion:(v. 5.3 server)

Trust: 0.8

vendor:red hatmodel:enterprise linux long lifescope:eqversion:(v. 5.6 server)

Trust: 0.8

vendor:red hatmodel:enterprise linux serverscope:eqversion:6

Trust: 0.8

vendor:red hatmodel:enterprise linux server eusscope:eqversion:6.0.z

Trust: 0.8

vendor:red hatmodel:enterprise linux server eusscope:eqversion:6.1.z

Trust: 0.8

vendor:red hatmodel:enterprise linux workstationscope:eqversion:6

Trust: 0.8

vendor:red hatmodel:rhel desktop workstationscope:eqversion:5 (client)

Trust: 0.8

vendor:necmodel:csviewscope:eqversion:/faq navigator

Trust: 0.8

vendor:necmodel:csviewscope:eqversion:/web questionnaire

Trust: 0.8

vendor:necmodel:pasolink nmsscope: - version: -

Trust: 0.8

vendor:necmodel:webotxscope:eqversion:enterprise edition v4.1 to v6.5

Trust: 0.8

vendor:necmodel:webotxscope:eqversion:standard edition v4.1 to v6.5

Trust: 0.8

vendor:necmodel:webotxscope:eqversion:standard-j edition v4.1 to v6.5

Trust: 0.8

vendor:necmodel:webotxscope:eqversion:web edition v4.1 to v6.5

Trust: 0.8

vendor:necmodel:webotx application serverscope:eqversion:enterprise edition v7.1 to v8.1

Trust: 0.8

vendor:necmodel:webotx application serverscope:eqversion:enterprise v8.2 to v8.4

Trust: 0.8

vendor:necmodel:webotx application serverscope:eqversion:express v8.2 to v8.4

Trust: 0.8

vendor:necmodel:webotx application serverscope:eqversion:foundation v8.2 to v8.4

Trust: 0.8

vendor:necmodel:webotx application serverscope:eqversion:standard edition v7.1 to v8.1

Trust: 0.8

vendor:necmodel:webotx application serverscope:eqversion:standard v8.2 to v8.4

Trust: 0.8

vendor:necmodel:webotx application serverscope:eqversion:standard-j edition v7.1 to v8.1

Trust: 0.8

vendor:necmodel:webotx enterprise service busscope:eqversion:v6.4 to v8.4

Trust: 0.8

vendor:necmodel:webotx portalscope:eqversion:v8.2 to v8.3

Trust: 0.8

vendor:necmodel:webotx sip application serverscope:eqversion:standard edition v7.1 to v8.1

Trust: 0.8

vendor:hitachimodel:groupmax collaborationscope:eqversion:- server

Trust: 0.8

vendor:hitachimodel:hirdb realtime monitorscope: - version: -

Trust: 0.8

vendor:hitachimodel:device managerscope:eqversion:software

Trust: 0.8

vendor:hitachimodel:global link managerscope:eqversion:software

Trust: 0.8

vendor:hitachimodel:it operations analyzerscope: - version: -

Trust: 0.8

vendor:hitachimodel:it operations directorscope: - version: -

Trust: 0.8

vendor:hitachimodel:provisioning managerscope:eqversion:software

Trust: 0.8

vendor:hitachimodel:replication managerscope:eqversion:software

Trust: 0.8

vendor:hitachimodel:tiered storage managerscope:eqversion:software

Trust: 0.8

vendor:hitachimodel:tuning managerscope:eqversion:software

Trust: 0.8

vendor:hitachimodel:web serverscope: - version: -

Trust: 0.8

vendor:hitachimodel:job management partner 1/automatic job management system 3scope:eqversion:- web operation assistant( english edition )

Trust: 0.8

vendor:hitachimodel:job management partner 1/performance management - web consolescope:eqversion:( overseas edition )

Trust: 0.8

vendor:hitachimodel:jp1/automatic job management system 2scope:eqversion:- web operation assistant

Trust: 0.8

vendor:hitachimodel:jp1/automatic job management system 3scope:eqversion:- web operation assistant

Trust: 0.8

vendor:hitachimodel:jp1/cm2/snmp system observerscope: - version: -

Trust: 0.8

vendor:hitachimodel:jp1/hicommand device managerscope: - version: -

Trust: 0.8

vendor:hitachimodel:jp1/hicommand provisioning managerscope: - version: -

Trust: 0.8

vendor:hitachimodel:jp1/hicommand replication monitorscope: - version: -

Trust: 0.8

vendor:hitachimodel:jp1/hicommand tiered storage managerscope: - version: -

Trust: 0.8

vendor:hitachimodel:jp1/hicommand tuning managerscope: - version: -

Trust: 0.8

vendor:hitachimodel:jp1/integrated managementscope:eqversion:- service support

Trust: 0.8

vendor:hitachimodel:jp1/it resource managementscope:eqversion:- manager

Trust: 0.8

vendor:hitachimodel:jp1/it service level managementscope:eqversion:- manager

Trust: 0.8

vendor:hitachimodel:jp1/performance managementscope:eqversion:- manager web option

Trust: 0.8

vendor:hitachimodel:jp1/performance managementscope:eqversion:- web console

Trust: 0.8

vendor:hitachimodel:jp1/serverconductor/control managerscope: - version: -

Trust: 0.8

vendor:hitachimodel:ucosminexus application serverscope:eqversion:enterprise

Trust: 0.8

vendor:hitachimodel:ucosminexus application serverscope:eqversion:express

Trust: 0.8

vendor:hitachimodel:ucosminexus application serverscope:eqversion:light

Trust: 0.8

vendor:hitachimodel:ucosminexus application serverscope:eqversion:smart edition

Trust: 0.8

vendor:hitachimodel:ucosminexus application serverscope:eqversion:standard

Trust: 0.8

vendor:hitachimodel:ucosminexus application serverscope:eqversion:standard-r

Trust: 0.8

vendor:hitachimodel:ucosminexus collaborationscope:eqversion:- server

Trust: 0.8

vendor:hitachimodel:ucosminexus developerscope:eqversion:01

Trust: 0.8

vendor:hitachimodel:ucosminexus developerscope:eqversion:light

Trust: 0.8

vendor:hitachimodel:ucosminexus developerscope:eqversion:professional

Trust: 0.8

vendor:hitachimodel:ucosminexus developerscope:eqversion:professional for plug-in

Trust: 0.8

vendor:hitachimodel:ucosminexus developerscope:eqversion:standard

Trust: 0.8

vendor:hitachimodel:ucosminexus navigationscope:eqversion:developer

Trust: 0.8

vendor:hitachimodel:ucosminexus navigationscope:eqversion:platform

Trust: 0.8

vendor:hitachimodel:ucosminexus navigationscope:eqversion:platform - authoring license

Trust: 0.8

vendor:hitachimodel:ucosminexus navigationscope:eqversion:platform - user license

Trust: 0.8

vendor:hitachimodel:ucosminexus primary serverscope:eqversion:base

Trust: 0.8

vendor:hitachimodel:ucosminexus servicescope:eqversion:architect

Trust: 0.8

vendor:hitachimodel:ucosminexus servicescope:eqversion:platform

Trust: 0.8

vendor:hitachimodel:ucosminexus servicescope:eqversion:platform - messaging

Trust: 0.8

vendor:hitachimodel:ucosminexus stream data platformscope:eqversion:- application framework

Trust: 0.8

vendor:hitachimodel:electronic form workflowscope:eqversion:standard set

Trust: 0.8

vendor:hitachimodel:electronic form workflowscope:eqversion:set

Trust: 0.8

vendor:hitachimodel:electronic form workflowscope:eqversion:developer client set

Trust: 0.8

vendor:hitachimodel:electronic form workflowscope:eqversion:developer set

Trust: 0.8

vendor:hitachimodel:electronic form workflowscope:eqversion:professional library set

Trust: 0.8

vendor:hitachimodel:electronic form workflowscope:eqversion:professional set

Trust: 0.8

vendor:fujitsumodel:internet navigware serverscope: - version: -

Trust: 0.8

vendor:fujitsumodel:interstage application development cycle managerscope: - version: -

Trust: 0.8

vendor:fujitsumodel:interstage application framework suitescope: - version: -

Trust: 0.8

vendor:fujitsumodel:interstage application serverscope: - version: -

Trust: 0.8

vendor:fujitsumodel:interstage apworksscope: - version: -

Trust: 0.8

vendor:fujitsumodel:interstage business application serverscope: - version: -

Trust: 0.8

vendor:fujitsumodel:interstage form coordinator workflowscope: - version: -

Trust: 0.8

vendor:fujitsumodel:interstage job workload serverscope: - version: -

Trust: 0.8

vendor:fujitsumodel:interstage list managerscope: - version: -

Trust: 0.8

vendor:fujitsumodel:interstage list worksscope: - version: -

Trust: 0.8

vendor:fujitsumodel:interstage service integratorscope: - version: -

Trust: 0.8

vendor:fujitsumodel:interstage studioscope: - version: -

Trust: 0.8

vendor:fujitsumodel:interstage web serverscope: - version: -

Trust: 0.8

vendor:fujitsumodel:interstage xml business activity recorderscope: - version: -

Trust: 0.8

vendor:fujitsumodel:systemwalker availability viewscope: - version: -

Trust: 0.8

vendor:fujitsumodel:systemwalker centric managerscope: - version: -

Trust: 0.8

vendor:fujitsumodel:systemwalker desktop inspectionscope: - version: -

Trust: 0.8

vendor:fujitsumodel:systemwalker it change managerscope: - version: -

Trust: 0.8

vendor:fujitsumodel:systemwalker it process masterscope: - version: -

Trust: 0.8

vendor:fujitsumodel:systemwalker resource coordinatorscope: - version: -

Trust: 0.8

vendor:fujitsumodel:systemwalker runbook automationscope: - version: -

Trust: 0.8

vendor:fujitsumodel:systemwalker service catalog managerscope: - version: -

Trust: 0.8

vendor:fujitsumodel:systemwalker service quality coordinatorscope: - version: -

Trust: 0.8

vendor:fujitsumodel:systemwalker software configuration managerscope: - version: -

Trust: 0.8

vendor:fujitsumodel:cloud infrastructure management softwarescope: - version: -

Trust: 0.8

sources: CERT/CC: VU#405811 // JVNDB: JVNDB-2011-002172 // NVD: CVE-2011-3192

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2011-3192
value: HIGH

Trust: 1.0

CARNEGIE MELLON: VU#405811
value: 16.01

Trust: 0.8

NVD: CVE-2011-3192
value: HIGH

Trust: 0.8

VULMON: CVE-2011-3192
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2011-3192
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

sources: CERT/CC: VU#405811 // VULMON: CVE-2011-3192 // JVNDB: JVNDB-2011-002172 // NVD: CVE-2011-3192

PROBLEMTYPE DATA

problemtype:CWE-400

Trust: 1.0

problemtype:CWE-399

Trust: 0.8

sources: JVNDB: JVNDB-2011-002172 // NVD: CVE-2011-3192

THREAT TYPE

remote

Trust: 0.1

sources: PACKETSTORM: 105792

TYPE

arbitrary, csrf

Trust: 0.1

sources: PACKETSTORM: 112043

CONFIGURATIONS

sources: JVNDB: JVNDB-2011-002172

EXPLOIT AVAILABILITY

sources: VULMON: CVE-2011-3192

PATCH

title:Fixed in Apache httpd 2.2.20url:http://httpd.apache.org/security/vulnerabilities_22.html#2.2.20

Trust: 0.8

title:Downloading the Apache HTTP Serverurl:http://httpd.apache.org/download.cgi

Trust: 0.8

title:Range header DoS vulnerability Apache HTTPD 1.3/2.x UPDATE 2url:http://mail-archives.apache.org/mod_mbox/httpd-announce/201108.mbox/%3C20110826103531.998348F82@minotaur.apache.org%3E

Trust: 0.8

title:Range header DoS vulnerability Apache HTTPD 1.3/2.xurl:http://mail-archives.apache.org/mod_mbox/httpd-announce/201108.mbox/%3C20110824161640.122D387DD@minotaur.apache.org%3E

Trust: 0.8

title:Apache HTTP Server 2.2.20 Releasedurl:http://www.apache.org/dist/httpd/Announcement2.2.html

Trust: 0.8

title:HT5002url:http://support.apple.com/kb/HT5002

Trust: 0.8

title:Changes with Apache 2.2.20url:http://www.apache.org/dist/httpd/CHANGES_2.2.20

Trust: 0.8

title:cisco-sa-20110830-apacheurl:http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20110830-apache

Trust: 0.8

title:HS11-020url:http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS11-020/index.html

Trust: 0.8

title:HS11-021url:http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS11-021/index.html

Trust: 0.8

title:HS11-022url:http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS11-022/index.html

Trust: 0.8

title:HS11-019url:http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS11-019/index.html

Trust: 0.8

title:HPSBOV02822 SSRT100966url:http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03517954

Trust: 0.8

title:HPSBUX02707 SSRT100626url:http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03025215

Trust: 0.8

title:HPSBUX02702 SSRT100606url:http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02997184

Trust: 0.8

title:7021867url:http://www-01.ibm.com/support/docview.wss?uid=swg27021867#8001

Trust: 0.8

title:4030863url:http://www-01.ibm.com/support/docview.wss?uid=swg24030863

Trust: 0.8

title:1512087url:http://www-01.ibm.com/support/docview.wss?uid=swg21512087

Trust: 0.8

title:J1008285url:http://www-01.ibm.com/support/docview.wss?uid=jpn1J1008285

Trust: 0.8

title:J1008222url:http://www-01.ibm.com/support/docview.wss?uid=jpn1J1008222

Trust: 0.8

title:2236url:https://www.miraclelinux.com/support/index.php?q=node/99&errata_id=2236

Trust: 0.8

title:NV11-005url:http://jpn.nec.com/security-info/secinfo/nv11-005.html

Trust: 0.8

title:SUSE-SU-2011:1010url:http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00011.html

Trust: 0.8

title:openSUSE-SU-2011:0993url:http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00006.html

Trust: 0.8

title:SUSE-SU-2011:1000url:http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00009.html

Trust: 0.8

title:SUSE-SU-2011:1007url:http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00010.html

Trust: 0.8

title:Oracle Critical Patch Update Advisory - January 2012url:http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html

Trust: 0.8

title:Oracle Critical Patch Update Advisory - July 2012url:http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.html

Trust: 0.8

title:Text Form of Oracle Critical Patch Update - July 2012 Risk Matricesurl:http://www.oracle.com/technetwork/topics/security/cpujul2012verbose-392736.html

Trust: 0.8

title:alert-cve-2011-3192-485304url:http://www.oracle.com/technetwork/topics/security/alert-cve-2011-3192-485304.html

Trust: 0.8

title:RHSA-2011:1369url:http://rhn.redhat.com/errata/RHSA-2011-1369.html

Trust: 0.8

title:RHSA-2011:1330url:http://rhn.redhat.com/errata/RHSA-2011-1330.html

Trust: 0.8

title:RHSA-2011:1294url:https://rhn.redhat.com/errata/RHSA-2011-1294.html

Trust: 0.8

title:RHSA-2011:1329url:http://rhn.redhat.com/errata/RHSA-2011-1329.html

Trust: 0.8

title:RHSA-2011:1300url:https://rhn.redhat.com/errata/RHSA-2011-1300.html

Trust: 0.8

title:RHSA-2011:1245url:https://rhn.redhat.com/errata/RHSA-2011-1245.html

Trust: 0.8

title:Ridocソフトウェア製品での「Apache HTTPD サーバーにおけるサービス運用妨害 (DoS) の脆弱性」についてurl:http://www.ricoh.co.jp/support/news/121114.html

Trust: 0.8

title:MDVSA-2011:130url:http://www.mandriva.com/en/support/security/advisories/?name=MDVSA-2011:130

Trust: 0.8

title:January 2012 Critical Patch Update Releasedurl:http://blogs.oracle.com/security/entry/january_2012_critical_patch_update

Trust: 0.8

title:CVE-2011-3192 Denial of Service vulnerability in Apache HTTP Serverurl:https://blogs.oracle.com/sunsecurity/entry/cve_2011_3192_denial_of1

Trust: 0.8

title:July 2012 Critical Patch Update Releasedurl:http://blogs.oracle.com/security/entry/july_2012_critical_patch_update

Trust: 0.8

title:cve_2011_3192_denial_ofurl:http://blogs.oracle.com/sunsecurity/entry/cve_2011_3192_denial_of

Trust: 0.8

title:USN-1199-1url:http://www.ubuntu.com/usn/USN-1199-1/

Trust: 0.8

title:interstage_as_201102url:http://software.fujitsu.com/jp/security/products-fujitsu/solution/interstage_as_201102.html

Trust: 0.8

title:cisco-sa-20110830-apacheurl:http://www.cisco.com/cisco/web/support/JP/110/1108/1108502_cisco-sa-20110830-apache-j.html

Trust: 0.8

title:HS11-021url:http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/HS11-021/index.html

Trust: 0.8

title:HS11-022url:http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/HS11-022/index.html

Trust: 0.8

title:HS11-019url:http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/HS11-019/index.html

Trust: 0.8

title:HS11-020url:http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/HS11-020/index.html

Trust: 0.8

title:VU#405811url:http://software.fujitsu.com/jp/security/vulnerabilities/vu405811.html

Trust: 0.8

title:Ubuntu Security Notice: apache2 vulnerabilityurl:https://vulmon.com/vendoradvisory?qidtp=ubuntu_security_notice&qid=USN-1199-1

Trust: 0.1

title:Cisco: Apache HTTPd Range Header Denial of Service Vulnerabilityurl:https://vulmon.com/vendoradvisory?qidtp=cisco_security_advisories_and_alerts_ciscoproducts&qid=cisco-sa-20110830-apache

Trust: 0.1

title:Debian Security Advisories: DSA-2298-2 apache2 -- denial of serviceurl:https://vulmon.com/vendoradvisory?qidtp=debian_security_advisories&qid=7227b6751a2a5332a53278f1881d559f

Trust: 0.1

title:Amazon Linux AMI: ALAS-2011-001url:https://vulmon.com/vendoradvisory?qidtp=amazon_linux_ami&qid=ALAS-2011-001

Trust: 0.1

title:Red Hat: Moderate: httpd security and bug fix updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20120542 - Security Advisory

Trust: 0.1

title: - url:https://github.com/Live-Hack-CVE/CVE-2011-3192

Trust: 0.1

title:MNCanyonurl:https://github.com/MNCanyon/MNCanyon

Trust: 0.1

title:haproxy-ddosurl:https://github.com/analytically/haproxy-ddos

Trust: 0.1

title:DDoS-Scripturl:https://github.com/Encapsulate/DDoS-Script

Trust: 0.1

title:Mind_helpurl:https://github.com/MNCanyon/Mind_help

Trust: 0.1

title:DC-p0turl:https://github.com/5p1n6a11/DC-p0t

Trust: 0.1

sources: VULMON: CVE-2011-3192 // JVNDB: JVNDB-2011-002172

EXTERNAL IDS

db:CERT/CCid:VU#405811

Trust: 2.6

db:NVDid:CVE-2011-3192

Trust: 2.4

db:BIDid:49303

Trust: 1.8

db:SECUNIAid:45606

Trust: 1.8

db:SECTRACKid:1025960

Trust: 1.8

db:OSVDBid:74721

Trust: 1.8

db:SECUNIAid:45937

Trust: 1.0

db:SECUNIAid:46125

Trust: 1.0

db:SECUNIAid:46000

Trust: 1.0

db:SECUNIAid:46126

Trust: 1.0

db:EXPLOIT-DBid:17696

Trust: 1.0

db:JVNDBid:JVNDB-2011-002172

Trust: 0.8

db:SECUNIAid:45865

Trust: 0.2

db:VULMONid:CVE-2011-3192

Trust: 0.1

db:HITACHIid:HS11-019

Trust: 0.1

db:PACKETSTORMid:104804

Trust: 0.1

db:PACKETSTORMid:105792

Trust: 0.1

db:PACKETSTORMid:105422

Trust: 0.1

db:PACKETSTORMid:112043

Trust: 0.1

db:PACKETSTORMid:104587

Trust: 0.1

db:PACKETSTORMid:117251

Trust: 0.1

sources: CERT/CC: VU#405811 // VULMON: CVE-2011-3192 // PACKETSTORM: 104804 // PACKETSTORM: 105792 // PACKETSTORM: 105422 // PACKETSTORM: 112043 // PACKETSTORM: 104587 // PACKETSTORM: 117251 // JVNDB: JVNDB-2011-002172 // NVD: CVE-2011-3192

REFERENCES

url:http://www.apache.org/dist/httpd/announcement2.2.html

Trust: 1.8

url:http://osvdb.org/74721

Trust: 1.8

url:http://secunia.com/advisories/45606

Trust: 1.8

url:http://www.securityfocus.com/bid/49303

Trust: 1.8

url:http://www.kb.cert.org/vuls/id/405811

Trust: 1.8

url:http://www.redhat.com/support/errata/rhsa-2011-1369.html

Trust: 1.0

url:https://lists.apache.org/thread.html/r1d201e3da31a2c8aa870c8314623caef7debd74a13d0f25205e26f15%40%3ccvs.httpd.apache.org%3e

Trust: 1.0

url:http://www.redhat.com/support/errata/rhsa-2011-1294.html

Trust: 1.0

url:https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3ccvs.httpd.apache.org%3e

Trust: 1.0

url:https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3ccvs.httpd.apache.org%3e

Trust: 1.0

url:https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3ccvs.httpd.apache.org%3e

Trust: 1.0

url:https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3ccvs.httpd.apache.org%3e

Trust: 1.0

url:https://oval.cisecurity.org/repository/search/definition/oval%3aorg.mitre.oval%3adef%3a14762

Trust: 1.0

url:http://marc.info/?l=bugtraq&m=134987041210674&w=2

Trust: 1.0

url:http://marc.info/?l=bugtraq&m=133951357207000&w=2

Trust: 1.0

url:http://secunia.com/advisories/46125

Trust: 1.0

url:http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00009.html

Trust: 1.0

url:https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3ccvs.httpd.apache.org%3e

Trust: 1.0

url:http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00011.html

Trust: 1.0

url:https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3ccvs.httpd.apache.org%3e

Trust: 1.0

url:http://secunia.com/advisories/45937

Trust: 1.0

url:http://www.redhat.com/support/errata/rhsa-2011-1329.html

Trust: 1.0

url:https://help.ecostruxureit.com/display/public/uadce725/security+fixes+in+struxureware+data+center+expert+v7.6.0

Trust: 1.0

url:http://www.oracle.com/technetwork/topics/security/cpuoct2011-330135.html

Trust: 1.0

url:https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3ccvs.httpd.apache.org%3e

Trust: 1.0

url:http://mail-archives.apache.org/mod_mbox/httpd-announce/201108.mbox/%3c20110824161640.122d387dd%40minotaur.apache.org%3e

Trust: 1.0

url:http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00008.html

Trust: 1.0

url:http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html

Trust: 1.0

url:http://marc.info/?l=bugtraq&m=133477473521382&w=2

Trust: 1.0

url:https://issues.apache.org/bugzilla/show_bug.cgi?id=51714

Trust: 1.0

url:https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3ccvs.httpd.apache.org%3e

Trust: 1.0

url:https://lists.apache.org/thread.html/r688df6f16f141e966a0a47f817e559312b3da27886f59116a94b273d%40%3ccvs.httpd.apache.org%3e

Trust: 1.0

url:http://blogs.oracle.com/security/entry/security_alert_for_cve_2011

Trust: 1.0

url:https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3ccvs.httpd.apache.org%3e

Trust: 1.0

url:https://oval.cisecurity.org/repository/search/definition/oval%3aorg.mitre.oval%3adef%3a18827

Trust: 1.0

url:http://www.mandriva.com/security/advisories?name=mdvsa-2011:130

Trust: 1.0

url:https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3ccvs.httpd.apache.org%3e

Trust: 1.0

url:http://marc.info/?l=bugtraq&m=131731002122529&w=2

Trust: 1.0

url:https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3ccvs.httpd.apache.org%3e

Trust: 1.0

url:http://archives.neohapsis.com/archives/fulldisclosure/2011-08/0285.html

Trust: 1.0

url:http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00011.html

Trust: 1.0

url:http://secunia.com/advisories/46000

Trust: 1.0

url:http://secunia.com/advisories/46126

Trust: 1.0

url:https://lists.apache.org/thread.html/re2e23465bbdb17ffe109d21b4f192e6b58221cd7aa8797d530b4cd75%40%3ccvs.httpd.apache.org%3e

Trust: 1.0

url:http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00006.html

Trust: 1.0

url:https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3ccvs.httpd.apache.org%3e

Trust: 1.0

url:http://securitytracker.com/id?1025960

Trust: 1.0

url:http://seclists.org/fulldisclosure/2011/aug/175

Trust: 1.0

url:http://www.cisco.com/en/us/products/products_security_advisory09186a0080b90d73.shtml

Trust: 1.0

url:http://www.redhat.com/support/errata/rhsa-2011-1245.html

Trust: 1.0

url:http://www.gossamer-threads.com/lists/apache/dev/401638

Trust: 1.0

url:http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.html

Trust: 1.0

url:http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00010.html

Trust: 1.0

url:https://bugzilla.redhat.com/show_bug.cgi?id=732928

Trust: 1.0

url:http://support.apple.com/kb/ht5002

Trust: 1.0

url:http://mail-archives.apache.org/mod_mbox/httpd-dev/201108.mbox/%3ccaapsnn2po-d-c4nqt_tes2rrwizr7urefhtkpwbc1b+k1dqc7g%40mail.gmail.com%3e

Trust: 1.0

url:http://www.redhat.com/support/errata/rhsa-2011-1330.html

Trust: 1.0

url:https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3ccvs.httpd.apache.org%3e

Trust: 1.0

url:https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3ccvs.httpd.apache.org%3e

Trust: 1.0

url:http://www.exploit-db.com/exploits/17696

Trust: 1.0

url:https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3ccvs.httpd.apache.org%3e

Trust: 1.0

url:http://www.ubuntu.com/usn/usn-1199-1

Trust: 1.0

url:https://oval.cisecurity.org/repository/search/definition/oval%3aorg.mitre.oval%3adef%3a14824

Trust: 1.0

url:http://www.redhat.com/support/errata/rhsa-2011-1300.html

Trust: 1.0

url:http://lists.apple.com/archives/security-announce/2011//oct/msg00003.html

Trust: 1.0

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/69396

Trust: 1.0

url:http://www.oracle.com/technetwork/topics/security/alert-cve-2011-3192-485304.html

Trust: 1.0

url:https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3ccvs.httpd.apache.org%3e

Trust: 1.0

url:http://marc.info/?l=bugtraq&m=132033751509019&w=2

Trust: 1.0

url:https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3ccvs.httpd.apache.org%3e

Trust: 1.0

url:http://www.mandriva.com/security/advisories?name=mdvsa-2013:150

Trust: 1.0

url:http://marc.info/?l=bugtraq&m=131551295528105&w=2

Trust: 1.0

url:http://blog.spiderlabs.com/2011/08/mitigation-of-apache-range-header-dos-attack.html

Trust: 0.8

url:http://mail-archives.apache.org/mod_mbox/httpd-announce/201108.mbox/%3c20110824161640.122d387dd@minotaur.apache.org%3e

Trust: 0.8

url:http://mail-archives.apache.org/mod_mbox/httpd-announce/201108.mbox/%3c20110826103531.998348f82@minotaur.apache.org%3e

Trust: 0.8

url:http://www.apache.org/dist/httpd/changes_2.2.20

Trust: 0.8

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2011-3192

Trust: 0.8

url:http://www.ipa.go.jp/security/ciadr/vul/20110831-apache.html

Trust: 0.8

url:https://www.jpcert.or.jp/at/2011/at110023.html

Trust: 0.8

url:http://jvn.jp/cert/jvnvu405811

Trust: 0.8

url:http://jvn.jp/tr/jvntr-2011-05

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2011-3192

Trust: 0.8

url:http://www.securitytracker.com/id?1025960

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2011-3192

Trust: 0.5

url:https://nvd.nist.gov/vuln/detail/cve-2011-0419

Trust: 0.3

url:http://h41183.www4.hp.com/signup_alerts.php?jumpid=hpsc_secbulletins

Trust: 0.3

url:https://h20566.www2.hp.com/portal/site/hpsc/public/kb/docdisplay/?docid=emr_na-c02964430

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2010-1452

Trust: 0.2

url:http://h20566.www2.hp.com/portal/site/hpsc/public/kb/secbullarchive/

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2011-1928

Trust: 0.2

url:http://secunia.com/vulnerability_intelligence/

Trust: 0.1

url:http://secunia.com/blog/242

Trust: 0.1

url:http://secunia.com/vulnerability_scanning/corporate/wsus_sccm_3rd_third_party_patching/

Trust: 0.1

url:http://secunia.com/advisories/secunia_security_advisories/

Trust: 0.1

url:https://ca.secunia.com/?page=viewadvisory&vuln_id=45865

Trust: 0.1

url:http://secunia.com/advisories/45865/

Trust: 0.1

url:http://secunia.com/vulnerability_scanning/personal/

Trust: 0.1

url:http://www.hitachi.co.jp/prod/comp/soft1/security/info/./vuls/hs11-019/index.html

Trust: 0.1

url:http://secunia.com/advisories/45865/#comments

Trust: 0.1

url:http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org

Trust: 0.1

url:http://secunia.com/advisories/about_secunia_advisories/

Trust: 0.1

url:https://www.redhat.com/mailman/listinfo/rhsa-announce

Trust: 0.1

url:https://access.redhat.com/kb/docs/doc-11259

Trust: 0.1

url:https://access.redhat.com/security/team/key/#package

Trust: 0.1

url:https://www.redhat.com/security/data/cve/cve-2011-3192.html

Trust: 0.1

url:https://rhn.redhat.com/errata/rhsa-2011-1369.html

Trust: 0.1

url:http://bugzilla.redhat.com/):

Trust: 0.1

url:https://access.redhat.com/security/team/contact/

Trust: 0.1

url:https://access.redhat.com/security/updates/classification/#important

Trust: 0.1

url:https://ftp.usa.hp.com/hprc

Trust: 0.1

url:https://www.hp.com/go/swa

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-3348

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-1623

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-4409

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-1468

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-1148

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-3182

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-1467

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-1471

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-0734

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-1470

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-2202

Trust: 0.1

url:http://h18000.www1.hp.com/products/servers/management/agents/index.html

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-4645

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-1945

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-2068

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-1938

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-3436

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-2483

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-0014

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-1464

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-1153

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-0195

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2009-0037

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-2192

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-2791

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-3189

Trust: 0.1

url:http://www.debian.org/security/faq

Trust: 0.1

url:http://www.debian.org/security/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-3368

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-4317

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-0031

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-3607

Trust: 0.1

url:http://h71000.www7.hp.com/openvms/products/ips/apache/csws_patches.html

Trust: 0.1

url:https://h20566.www2.hp.com/portal/site/hpsc/public/kb/

Trust: 0.1

sources: CERT/CC: VU#405811 // PACKETSTORM: 104804 // PACKETSTORM: 105792 // PACKETSTORM: 105422 // PACKETSTORM: 112043 // PACKETSTORM: 104587 // PACKETSTORM: 117251 // JVNDB: JVNDB-2011-002172 // NVD: CVE-2011-3192

CREDITS

HP

Trust: 0.3

sources: PACKETSTORM: 105422 // PACKETSTORM: 112043 // PACKETSTORM: 117251

SOURCES

db:CERT/CCid:VU#405811
db:VULMONid:CVE-2011-3192
db:PACKETSTORMid:104804
db:PACKETSTORMid:105792
db:PACKETSTORMid:105422
db:PACKETSTORMid:112043
db:PACKETSTORMid:104587
db:PACKETSTORMid:117251
db:JVNDBid:JVNDB-2011-002172
db:NVDid:CVE-2011-3192

LAST UPDATE DATE

2026-08-28T20:54:48.285000+00:00


SOURCES UPDATE DATE

db:CERT/CCid:VU#405811date:2011-09-19T00:00:00
db:VULMONid:CVE-2011-3192date:2022-09-19T00:00:00
db:JVNDBid:JVNDB-2011-002172date:2017-07-25T00:00:00
db:NVDid:CVE-2011-3192date:2026-06-16T23:32:50.453

SOURCES RELEASE DATE

db:CERT/CCid:VU#405811date:2011-08-26T00:00:00
db:VULMONid:CVE-2011-3192date:2011-08-29T00:00:00
db:PACKETSTORMid:104804date:2011-09-06T04:48:58
db:PACKETSTORMid:105792date:2011-10-14T05:53:11
db:PACKETSTORMid:105422date:2011-09-29T18:05:00
db:PACKETSTORMid:112043date:2012-04-20T20:15:33
db:PACKETSTORMid:104587date:2011-08-30T14:42:37
db:PACKETSTORMid:117251date:2012-10-10T02:28:54
db:JVNDBid:JVNDB-2011-002172date:2011-09-01T00:00:00
db:NVDid:CVE-2011-3192date:2011-08-29T15:55:02.017