VULNERABILITY INTELLIGENCE
CVE-2011-4415
CVSS score1.2 LOW
EPSS probability4.72%
CISA KEVNot currently listed
Published2011-11-08
Last modified2026-06-16
Description
The ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, does not restrict the size of values of environment variables, which allows local users to cause a denial of service (memory consumption or NULL ... .