CVE-2011-3607

Publication date 8 November 2011

Last updated 24 July 2024


Ubuntu priority

Integer overflow in the ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, allows local users to gain privileges via a .htaccess file with a crafted SetEnvIf directive, in conjunction with a crafted HTTP request header, leading to a heap-based buffer overflow.

Status

Package Ubuntu Release Status
apache2 11.10 oneiric
Fixed 2.2.20-1ubuntu1.2
11.04 natty
Fixed 2.2.17-1ubuntu1.5
10.10 maverick
Fixed 2.2.16-1ubuntu3.5
10.04 LTS lucid
Fixed 2.2.14-5ubuntu8.8
8.04 LTS hardy
Fixed 2.2.8-1ubuntu0.23

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
apache2