AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2011-4415

LOW · CVSS 1.2 EPSS 3.10%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2011-11-08 · Last synced 2026-08-04

CyberRota Analysis

This is a low severity vulnerability with a CVSS score of 1.2. It affects Apache. It may lead to a denial-of-service condition.

CVE
CVE-2011-4415
Severity
LOW
CVSS
1.2
EPSS
3.10%
Apache

Original NVD Description

The ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, does not restrict the size of values of environment variables, which allows local users to cause a denial of service (memory consumption or NULL pointer dereference) via a .htaccess file with a crafted SetEnvIf directive, in conjunction with a crafted HTTP request header, related to (1) the "len +=" statement and (2) the apr_pcalloc function call, a different vulnerability than CVE-2011-3607.