CVE-2011-3192 httpd: multiple ranges DoS
Issue
- A remote DoS flaw was discovered in the way Apache httpd server handled Range HTTP headers: CVE-2011-3192, also known as "Apache killer"
- The "Apache Killer" threat has received a lot of attention in the IT trade press, e.g.
- http://www.theregister.co.uk/2011/08/24/devastating_apache_vuln/
- http://www.fastcompany.com/1776321/the-biggest-little-threat-to-kill-the-internet-you-didnt-know-about
- http://www.darkreading.com/vulnerability-management/167901026/security/attacks-breaches/231600219/workarounds-issued-for-apache-killer-attack.html
Environment
Apache httpd is affected, and in particular the versions included in the following products:
- JBoss Enterprise Web Server (EWS) 1.0
- Red Hat Enterprise Linux 6
- Red Hat Enterprise Linux 5
- Red Hat Enterprise Linux 4
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.