CVE-2011-3639 (CNNVD-201111-509)
中文标题:
Apache HTTP Server 输入验证错误漏洞
英文标题:
The mod_proxy module in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x before 2.2.18, when th...
漏洞描述
中文描述:
Apache HTTP Server是美国阿帕奇(Apache)基金会的一款开源网页服务器。该服务器具有快速、可靠且可通过简单的API进行扩充的特点。 Apache HTTP Server 2.0.x版本至2.0.64版本、2.2.x版本至2.2.18之前版本存在输入验证错误漏洞。远程攻击者利用该漏洞使用HTTP/0.9协议和包含@的格式错误的URI向Intranet服务器发送请求。
英文描述:
The mod_proxy module in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x before 2.2.18, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers by using the HTTP/0.9 protocol with a malformed URI containing an initial @ (at sign) character. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-3368.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| apache | http_server | 2.0.11 | - | - |
cpe:2.3:a:apache:http_server:2.0.11:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.12 | - | - |
cpe:2.3:a:apache:http_server:2.0.12:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.13 | - | - |
cpe:2.3:a:apache:http_server:2.0.13:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.14 | - | - |
cpe:2.3:a:apache:http_server:2.0.14:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.15 | - | - |
cpe:2.3:a:apache:http_server:2.0.15:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.16 | - | - |
cpe:2.3:a:apache:http_server:2.0.16:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.17 | - | - |
cpe:2.3:a:apache:http_server:2.0.17:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.18 | - | - |
cpe:2.3:a:apache:http_server:2.0.18:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.19 | - | - |
cpe:2.3:a:apache:http_server:2.0.19:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.20 | - | - |
cpe:2.3:a:apache:http_server:2.0.20:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.21 | - | - |
cpe:2.3:a:apache:http_server:2.0.21:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.22 | - | - |
cpe:2.3:a:apache:http_server:2.0.22:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.23 | - | - |
cpe:2.3:a:apache:http_server:2.0.23:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.24 | - | - |
cpe:2.3:a:apache:http_server:2.0.24:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.25 | - | - |
cpe:2.3:a:apache:http_server:2.0.25:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.26 | - | - |
cpe:2.3:a:apache:http_server:2.0.26:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.27 | - | - |
cpe:2.3:a:apache:http_server:2.0.27:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.28 | - | - |
cpe:2.3:a:apache:http_server:2.0.28:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.29 | - | - |
cpe:2.3:a:apache:http_server:2.0.29:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.30 | - | - |
cpe:2.3:a:apache:http_server:2.0.30:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.31 | - | - |
cpe:2.3:a:apache:http_server:2.0.31:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.32 | - | - |
cpe:2.3:a:apache:http_server:2.0.32:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.33 | - | - |
cpe:2.3:a:apache:http_server:2.0.33:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.34 | - | - |
cpe:2.3:a:apache:http_server:2.0.34:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.35 | - | - |
cpe:2.3:a:apache:http_server:2.0.35:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.36 | - | - |
cpe:2.3:a:apache:http_server:2.0.36:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.37 | - | - |
cpe:2.3:a:apache:http_server:2.0.37:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.38 | - | - |
cpe:2.3:a:apache:http_server:2.0.38:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.39 | - | - |
cpe:2.3:a:apache:http_server:2.0.39:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.40 | - | - |
cpe:2.3:a:apache:http_server:2.0.40:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.41 | - | - |
cpe:2.3:a:apache:http_server:2.0.41:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.42 | - | - |
cpe:2.3:a:apache:http_server:2.0.42:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.43 | - | - |
cpe:2.3:a:apache:http_server:2.0.43:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.44 | - | - |
cpe:2.3:a:apache:http_server:2.0.44:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.45 | - | - |
cpe:2.3:a:apache:http_server:2.0.45:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.46 | - | - |
cpe:2.3:a:apache:http_server:2.0.46:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.47 | - | - |
cpe:2.3:a:apache:http_server:2.0.47:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.48 | - | - |
cpe:2.3:a:apache:http_server:2.0.48:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.49 | - | - |
cpe:2.3:a:apache:http_server:2.0.49:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.50 | - | - |
cpe:2.3:a:apache:http_server:2.0.50:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.51 | - | - |
cpe:2.3:a:apache:http_server:2.0.51:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.52 | - | - |
cpe:2.3:a:apache:http_server:2.0.52:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.53 | - | - |
cpe:2.3:a:apache:http_server:2.0.53:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.54 | - | - |
cpe:2.3:a:apache:http_server:2.0.54:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.55 | - | - |
cpe:2.3:a:apache:http_server:2.0.55:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.56 | - | - |
cpe:2.3:a:apache:http_server:2.0.56:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.57 | - | - |
cpe:2.3:a:apache:http_server:2.0.57:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.58 | - | - |
cpe:2.3:a:apache:http_server:2.0.58:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.59 | - | - |
cpe:2.3:a:apache:http_server:2.0.59:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.61 | - | - |
cpe:2.3:a:apache:http_server:2.0.61:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.63 | - | - |
cpe:2.3:a:apache:http_server:2.0.63:*:*:*:*:*:*:*
|
| apache | http_server | 2.2.0 | - | - |
cpe:2.3:a:apache:http_server:2.2.0:*:*:*:*:*:*:*
|
| apache | http_server | 2.2.1 | - | - |
cpe:2.3:a:apache:http_server:2.2.1:*:*:*:*:*:*:*
|
| apache | http_server | 2.2.2 | - | - |
cpe:2.3:a:apache:http_server:2.2.2:*:*:*:*:*:*:*
|
| apache | http_server | 2.2.3 | - | - |
cpe:2.3:a:apache:http_server:2.2.3:*:*:*:*:*:*:*
|
| apache | http_server | 2.2.4 | - | - |
cpe:2.3:a:apache:http_server:2.2.4:*:*:*:*:*:*:*
|
| apache | http_server | 2.2.6 | - | - |
cpe:2.3:a:apache:http_server:2.2.6:*:*:*:*:*:*:*
|
| apache | http_server | 2.2.8 | - | - |
cpe:2.3:a:apache:http_server:2.2.8:*:*:*:*:*:*:*
|
| apache | http_server | 2.2.9 | - | - |
cpe:2.3:a:apache:http_server:2.2.9:*:*:*:*:*:*:*
|
| apache | http_server | 2.2.10 | - | - |
cpe:2.3:a:apache:http_server:2.2.10:*:*:*:*:*:*:*
|
| apache | http_server | 2.2.11 | - | - |
cpe:2.3:a:apache:http_server:2.2.11:*:*:*:*:*:*:*
|
| apache | http_server | 2.2.12 | - | - |
cpe:2.3:a:apache:http_server:2.2.12:*:*:*:*:*:*:*
|
| apache | http_server | 2.2.13 | - | - |
cpe:2.3:a:apache:http_server:2.2.13:*:*:*:*:*:*:*
|
| apache | http_server | 2.2.14 | - | - |
cpe:2.3:a:apache:http_server:2.2.14:*:*:*:*:*:*:*
|
| apache | http_server | 2.2.15 | - | - |
cpe:2.3:a:apache:http_server:2.2.15:*:*:*:*:*:*:*
|
| apache | http_server | 2.2.16 | - | - |
cpe:2.3:a:apache:http_server:2.2.16:*:*:*:*:*:*:*
|
| apache | http_server | 2.2.17 | - | - |
cpe:2.3:a:apache:http_server:2.2.17:*:*:*:*:*:*:*
|
| apache | http_server2.0a1 | * | - | - |
cpe:2.3:a:apache:http_server2.0a1:*:*:*:*:*:*:*:*
|
| apache | http_server2.0a2 | * | - | - |
cpe:2.3:a:apache:http_server2.0a2:*:*:*:*:*:*:*:*
|
| apache | http_server2.0a3 | * | - | - |
cpe:2.3:a:apache:http_server2.0a3:*:*:*:*:*:*:*:*
|
| apache | http_server2.0a4 | * | - | - |
cpe:2.3:a:apache:http_server2.0a4:*:*:*:*:*:*:*:*
|
| apache | http_server2.0a5 | * | - | - |
cpe:2.3:a:apache:http_server2.0a5:*:*:*:*:*:*:*:*
|
| apache | http_server2.0a6 | * | - | - |
cpe:2.3:a:apache:http_server2.0a6:*:*:*:*:*:*:*:*
|
| apache | http_server2.0a7 | * | - | - |
cpe:2.3:a:apache:http_server2.0a7:*:*:*:*:*:*:*:*
|
| apache | http_server2.0a8 | * | - | - |
cpe:2.3:a:apache:http_server2.0a8:*:*:*:*:*:*:*:*
|
| apache | http_server2.0a9 | * | - | - |
cpe:2.3:a:apache:http_server2.0a9:*:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
AV:N/AC:M/Au:N/C:N/I:P/A:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2011-3639 |
2025-11-11 15:18:24 | 2025-11-11 07:33:17 |
| NVD | nvd_CVE-2011-3639 |
2025-11-11 14:53:44 | 2025-11-11 07:42:07 |
| CNNVD | cnnvd_CNNVD-201111-509 |
2025-11-11 15:09:14 | 2025-11-11 07:49:58 |
| EXPLOITDB | exploitdb_EDB-36663 |
2025-11-11 15:05:25 | 2025-11-11 08:33:36 |
版本与语言
安全公告
变更历史
查看详细变更
- references_count: 4 -> 7
- tags_count: 0 -> 4
- data_sources: ['cnnvd', 'cve', 'nvd'] -> ['cnnvd', 'cve', 'exploitdb', 'nvd']
查看详细变更
- vulnerability_type: 未提取 -> 输入验证错误
- cnnvd_id: 未提取 -> CNNVD-201111-509
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- cvss_score: 未提取 -> 4.3
- cvss_vector: NOT_EXTRACTED -> AV:N/AC:M/Au:N/C:N/I:P/A:N
- cvss_version: NOT_EXTRACTED -> 2.0
- affected_products_count: 0 -> 76
- data_sources: ['cve'] -> ['cve', 'nvd']