Release date:
Updated on:
Affected Systems:
Apache Group Apache HTTP Server 2.2.x
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2011-3348
Apache HTTP Server is an open-source Web Server of the Apache Software Foundation. It can be run in most computer operating systems. It is widely used for cross-platform and security, is one of the most popular Web server software.
Apache HTTP Server mod_proxy_balancer has a security vulnerability. Malicious users can exploit this vulnerability to cause DoS attacks.
This vulnerability is caused by an error in malformed HTTP request processing in mod_proxy_ajp when combined with mod_proxy_balancer. By sending a specially crafted HTTP request, the backend server may fail and the temporary DoS will not end until the retry times out.
<* Source: vendor
Link: http://httpd.apache.org/security/vulnerabilities_22.html#2.2.21
Http://secunia.com/advisories/46013/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://httpd.apache.org/