CVE-2006-3747

Advisory lineage Upstream: 0 Downstream: 4
Modified
Published: 28 Jul 2006, 18:00
Last modified:07 Aug 2024, 18:39

Vulnerability Summary

Overall Risk (default)
high
58/100
CVSS Score
7.6 HIGH
v2.0 (nvd)
EPSS Score
90.02% CRITICAL
90% probability -2.72%
KEV
Not listed
Ransomware
No reports
Public exploits
5 found
Dark Web
Not detected

Timeline

28 Jul 2006, 18:00
Published
Vulnerability first disclosed
07 Aug 2024, 18:39
Last Modified
Vulnerability information updated

Description

Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2, when RewriteEngine is enabled, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted URLs that are not properly handled using certain rewrite rules.

CVSS Metrics

  • v2.0HIGHScore: 7.6AV:N/AC:H/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 90.02% Percentile: 100%

Techniques & Countermeasures

  • CWE-189Numeric Errors

    Weaknesses in this category are related to improper calculation or conversion of numbers.

Affected Systems

  • UnknownHTTP Server

    ≥ 1.3.28, < 1.3.37 | ≥ 2.0.46, < 2.0.59 | ≥ 2.2.0, < 2.2.3

  • canonicalubuntu_linux

    5.04 | 5.10 | 6.06

  • debiandebian_linux

    3.1

References (90)