MEDIUM · 4.3

CVE-2011-0419

Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in l...

Vulnerability Description

Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac OS X 10.6, Oracle Solaris 10, and Android, allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via *? sequences in the first argument, as demonstrated by attacks against mod_autoindex in httpd.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:N/I:N/A:P
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL

Affected Products

VendorProductVersions
ApachePortable Runtime< 1.4.3
ApacheHttp Server>= 2.0.0, <= 2.0.65
AppleMac Os X10.6.0
FreebsdFreebsdAll versions
GoogleAndroidAll versions
NetbsdNetbsd5.1
OpenbsdOpenbsd4.8
OracleSolaris10
DebianDebian Linux5.0
SuseLinux Enterprise Server10

Related Weaknesses (CWE)

References

FAQ

What is CVE-2011-0419?

CVE-2011-0419 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in l...

How severe is CVE-2011-0419?

CVE-2011-0419 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2011-0419?

Check the references section above for vendor advisories and patch information. Affected products include: Apache Portable Runtime, Apache Http Server, Apple Mac Os X, Freebsd Freebsd, Google Android.