Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-8734

Опубликовано: 16 окт. 2017
Источник: debian

Описание

Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-service attack caused by exponential XML entity expansion. The attack can cause the targeted process to consume an excessive amount of CPU resources or memory.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
subversionfixed1.9.5-1package
subversionfixed1.8.10-6+deb8u5jessiepackage
subversionno-dsawheezypackage

Примечания

  • Above wheezy entry workarounded; binary packages not affected (since in wheezy build against Neon as HTTP

  • library), though source is. (unimporant) for individual lines is not supported, thus workaround by marking

  • as no-dsa.

  • https://subversion.apache.org/security/CVE-2016-8734-advisory.txt

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 8 лет назад

Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-service attack caused by exponential XML entity expansion. The attack can cause the targeted process to consume an excessive amount of CPU resources or memory.

CVSS3: 4.4
redhat
около 9 лет назад

Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-service attack caused by exponential XML entity expansion. The attack can cause the targeted process to consume an excessive amount of CPU resources or memory.

CVSS3: 6.5
nvd
больше 8 лет назад

Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-service attack caused by exponential XML entity expansion. The attack can cause the targeted process to consume an excessive amount of CPU resources or memory.

suse-cvrf
около 9 лет назад

Security update for subversion

CVSS3: 6.5
github
больше 3 лет назад

Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-service attack caused by exponential XML entity expansion. The attack can cause the targeted process to consume an excessive amount of CPU resources or memory.