The fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library 1.4.3 and 1.4.4, and the Apache HTTP Server 2.2.18, allows remote attackers to cause a denial of service (infinite loop) via a URI that does not match unspecified types of wildcard patterns, as demonstrated by attacks against mod_autoindex in httpd when a /*/WEB-INF/ configuration pattern is used. NOTE: this issue exists because of an incorrect fix for CVE-2011-0419.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade aprUpgrade apr-docsUpgrade apr-devel | Dec 1, 2016 | May 24, 2011 |
| Debian | — | Upgrade apr | Jul 30, 2024 | May 24, 2011 |
| Freebsd | — | Upgrade apr1 | Dec 10, 2025 | May 23, 2011 |
| Gentoo Linux | — | Upgrade dev-libs/apr-util.Upgrade dev-libs/apr. | Oct 30, 2017 | May 24, 2011 |
| Hpsmh | — | Upgrade to the latest version of HP System Management Homepage | Oct 13, 2015 | May 24, 2011 |
| Oracle_linux | — | Upgrade aprUpgrade apr-develUpgrade apr-docs | Oct 16, 2024 | May 24, 2011 |
| Suse | — | Upgrade libapr1-32bitUpgrade libapr1-0Upgrade libapr1-devel-32bitUpgrade apr-develUpgrade libapr1Upgrade libapr1-devel | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libapr1Upgrade libapr0 | Nov 8, 2024 | May 24, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub