PT-2011-4554 · Apache+3 · Apache Http Server+3

CVE-2011-3639

·

Publicado

2011-11-30

·

Atualizado

2023-02-13

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.0.x through 2.0.64 Apache HTTP Server versions 2.2.x before 2.2.18
Description The issue arises from the mod proxy module's improper interaction with RewriteRule and ProxyPassMatch pattern matches when configured as a reverse proxy. This allows remote attackers to send requests to intranet servers by using the HTTP/0.9 protocol with a malformed URI containing an initial @ (at sign) character.
Recommendations For Apache HTTP Server versions 2.0.x through 2.0.64, update to a version that includes the complete fix for the issue. For Apache HTTP Server versions 2.2.x before 2.2.18, update to version 2.2.18 or later. As a temporary workaround, consider restricting access to the mod proxy module until a patch is available.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CESA-2012_0128
CVE-2011-3639
DSA-2405-1
RHSA-2012:0128
RHSA-2012:0323
RHSA-2012_0128
RHSA-2012_0323

Produtos afetados

Apache Http Server
Centos
Red Hat
Suse