CVE-2006-3747

Severity CVSS v4.0:
Pending analysis
Type:
CWE-189 Numeric Errors
Publication date:
28/07/2006
Last modified:
03/04/2025

Description

Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2, when RewriteEngine is enabled, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted URLs that are not properly handled using certain rewrite rules.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* 1.3.28 (including) 1.3.37 (excluding)
cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* 2.0.46 (including) 2.0.59 (excluding)
cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* 2.2.0 (including) 2.2.3 (excluding)
cpe:2.3:o:canonical:ubuntu_linux:5.04:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:5.10:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools