CVE-2011-3192 is a denial-of-service vulnerability affecting Apache HTTP Server versions 1.3.x, 2.0.x up to 2.0.64, and 2.2.x up to 2.2.19. Attackers can exploit this flaw by sending a specially crafted Range header with multiple overlapping ranges, leading to excessive memory and CPU consumption on the server. This vulnerability carries a high severity CVSS score of 7.8, indicating a critical impact. It is easily exploitable remotely with low attack complexity and no authentication required, resulting in a complete denial of service. The vulnerability was actively exploited in the wild in August 2011, with exploit code readily available in Metasploit and ExploitDB. It garnered significant community discussion and media coverage, including reports of its integration into DDoS botnet clients.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.35, < 2.0.65CPE matchmatch criteria | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* | ||
>= 2.2.0, < 2.2.20CPE matchmatch criteria | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* | ||
11.3CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:11.3:*:*:*:*:*:*:* | ||
11.4CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:11.4:*:*:*:*:*:*:* | ||
10CPE matchmatch criteria | cpe:2.3:o:suse:linux_enterprise_server:10:sp2:*:*:-:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.