Description
A denial of service vulnerability has been found in the way the multiple
overlapping ranges are handled by the Apache HTTPD server:
http://seclists.org/fulldisclosure/2011/Aug/175
An attack tool is circulating in the wild. Active use of this tools has
been observed. The attack can be done remotely and with a modest number of requests can
cause very significant memory and CPU usage on the server.
Affected Apache versions (1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19).
Remediation
Upgrade to the latest version of Apache HTTP Server (2.2.20 or later), available from the Apache HTTP Server Project Web site.
References
Related Vulnerabilities
Atlassian Jira Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-20415)
OpenSSL Resource Management Errors Vulnerability (CVE-2011-3210)
XWiki Improper Encoding or Escaping of Output Vulnerability (CVE-2023-26472)
PostgreSQL CVE-2023-5868 Vulnerability (CVE-2023-5868)
PostgreSQL Improper Control of Dynamically-Managed Code Resources Vulnerability (CVE-2022-2625)