10053—Apache Range Header DoS (CVE-2011-3192)
PUBLISHEDsecurity alertMedium
Active
Metadata
摘要
The byterange filter in earlier versions of the Apache HTTP Server allows remote attackers to cause a denial of service (memory and CPU exhaustion) via a Range request header that identifies multiple overlapping ranges. This issue was exploited in the wild in August 2011.Produced too many false positives and is no longer relevant.
解决方案
Upgrade your Apache server to a currently stable version. Alternative solutions or workarounds are outlined in the references.