CVE-2011-0419

Apache Portable Runtime < 1.4.3 - Denial of Service via fnmatch *? Sequence Handling

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2011-0419. PoCs published by Maksymilian Arciemowicz.

AI-analyzed exploit summary This exploit targets a denial-of-service vulnerability in Apache APR versions prior to 1.4.4 by sending a crafted HTTP request with a long query string to a directory with mod_autoindex enabled. The PoC creates a long filename and a malicious .htaccess file to trigger excessive CPU usage.

Description

Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac OS X 10.6, Oracle Solaris 10, and Android, allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via *? sequences in the first argument, as demonstrated by attacks against mod_autoindex in httpd.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Maksymilian Arciemowicz · phpdoslinux
https://www.exploit-db.com/exploits/35738

This exploit targets a denial-of-service vulnerability in Apache APR versions prior to 1.4.4 by sending a crafted HTTP request with a long query string to a directory with mod_autoindex enabled. The PoC creates a long filename and a malicious .htaccess file to trigger excessive CPU usage.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Apache APR < 1.4.4
No auth needed
Prerequisites: Directory with mod_autoindex enabled · Ability to create files in the target directory
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (58)

Core 58
Core References
Not Applicable, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/44574
Issue Tracking, Mailing List, Third Party Advisory vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=131731002122529&w=2
Issue Tracking, Mailing List, Third Party Advisory vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=134987041210674&w=2
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.mail-archive.com/dev%40apr.apache.org/msg23976.html
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/48308
Exploit, Third Party Advisory third-party-advisory x_refsource_sreasonres
http://securityreason.com/achievement_securityalert/98
Issue Tracking, Mailing List, Third Party Advisory vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=131551295528105&w=2
Issue Tracking, Mailing List, Third Party Advisory vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=132033751509019&w=2
Third Party Advisory x_refsource_misc
http://cxib.net/stuff/apr_fnmatch.txts
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1025527
Patch, Vendor Advisory x_refsource_confirm
http://svn.apache.org/viewvc?view=revision&revision=1098188
Broken Link x_refsource_confirm
http://www.apache.org/dist/apr/CHANGES-APR-1.4
Patch, Vendor Advisory x_refsource_confirm
http://www.apache.org/dist/apr/Announcement1.x.html
Patch, Vendor Advisory x_refsource_confirm
http://svn.apache.org/viewvc?view=revision&revision=1098799
Vendor Advisory x_refsource_confirm
http://httpd.apache.org/security/vulnerabilities_22.html
Exploit, Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/8246
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2011/dsa-2237
Third Party Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2011-0897.html
Issue Tracking, Patch, Third Party Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=703390
Not Applicable, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/44564
Patch, Vendor Advisory x_refsource_confirm
http://www.apache.org/dist/httpd/Announcement2.2.html
Not Applicable, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/44490
Patch, Third Party Advisory x_refsource_misc
http://cxib.net/stuff/apache.fnmatch.phps
Third Party Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2011-0896.html
Third Party Advisory x_refsource_confirm
http://support.apple.com/kb/HT5002
Broken Link vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2011:084
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.mail-archive.com/dev%40apr.apache.org/msg23961.html
Broken Link vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2013:150
Third Party Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2011-0507.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00011.html
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.mail-archive.com/dev%40apr.apache.org/msg23960.html

Scores

EPSS 0.3041
EPSS Percentile 98.0%

Details

CWE
CWE-770
Status published
Products (12)
apache/http_server 2.0.0 - 2.0.65
apache/portable_runtime < 1.4.3
apple/mac_os_x 10.6.0
debian/debian_linux 5.0
debian/debian_linux 6.0
debian/debian_linux 7.0
freebsd/freebsd
google/android
netbsd/netbsd 5.1
openbsd/openbsd 4.8
... and 2 more
Published May 16, 2011
Tracked Since Feb 18, 2026