7.6

CVE-2006-3747

Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2, when RewriteEngine is enabled, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted URLs that are not properly handled using certain rewrite rules.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ApacheHTTP Server Version >= 1.3.28 < 1.3.37
ApacheHTTP Server Version >= 2.0.46 < 2.0.59
ApacheHTTP Server Version >= 2.2.0 < 2.2.3
CanonicalUbuntu Linux Version5.04
CanonicalUbuntu Linux Version5.10
CanonicalUbuntu Linux Version6.06
DebianDebian Linux Version3.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 92.66% 0.997
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.6 4.9 10
AV:N/AC:H/Au:N/C:C/I:C/A:C
http://marc.info/?l=bugtraq&m=130497311408250&w=2
Third Party Advisory
Mailing List
http://www.us-cert.gov/cas/techalerts/TA08-150A.html
Third Party Advisory
US Government Resource
http://lwn.net/Alerts/194228/
Third Party Advisory
Mailing List
http://securitytracker.com/id?1016601
Third Party Advisory
VDB Entry
http://www.kb.cert.org/vuls/id/395412
Third Party Advisory
US Government Resource
http://www.securityfocus.com/bid/19204
Third Party Advisory
VDB Entry