Modified
Published: 16 May 2011, 17:00
Last modified:06 Aug 2024, 21:51

Vulnerability Summary

Overall Risk (default)
medium
37/100
CVSS Score
4.3 MEDIUM
v2.0 (nvd)
EPSS Score
48.78% HIGH
49% probability -9.14%
KEV
Not listed
Ransomware
No reports
Public exploits
3 found
Dark Web
Not detected

Timeline

16 May 2011, 17:00
Published
Vulnerability first disclosed
06 Aug 2024, 21:51
Last Modified
Vulnerability information updated

Description

Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac OS X 10.6, Oracle Solaris 10, and Android, allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via *? sequences in the first argument, as demonstrated by attacks against mod_autoindex in httpd.

CVSS Metrics

  • v2.0MEDIUMScore: 4.3AV:N/AC:M/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 48.78% Percentile: 98%

Techniques & Countermeasures

  • CWE-770Allocation of Resources Without Limits or Throttling

    The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Affected Systems

  • UnknownHTTP Server

    ≥ 2.0.0, ≤ 2.0.65 | ≥ 2.2.0, ≤ 2.2.18

  • apacheportable_runtime

    < 1.4.3

  • applemac_os_x

    10.6.0

  • debiandebian_linux

    5.0 | 6.0 | 7.0

  • netbsdnetbsd

    5.1

  • openbsdopenbsd

    4.8

  • UnknownSolaris

    10

  • suselinux_enterprise_server

    10:sp3

References (58)