Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-8734

Опубликовано: 29 нояб. 2016
Источник: redhat
CVSS3: 4.4
CVSS2: 3.5

Описание

Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-service attack caused by exponential XML entity expansion. The attack can cause the targeted process to consume an excessive amount of CPU resources or memory.

Меры по смягчению последствий

Only Apache+Subversion servers that have the "DontDoThatConfigFile" configuration option present are affected by this flaw. This option is not enabled in default httpd or mod_dav_svn configuration as shipped with Red Hat Enterprise Linux.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5subversionNot affected
Red Hat Enterprise Linux 6subversionNot affected
Red Hat Enterprise Linux 7subversionWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-776
https://bugzilla.redhat.com/show_bug.cgi?id=1397403subversion: unrestricted XML entity expansion in mod_dontdothat and Subversion clients using http(s)://

4.4 Medium

CVSS3

3.5 Low

CVSS2

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 8 лет назад

Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-service attack caused by exponential XML entity expansion. The attack can cause the targeted process to consume an excessive amount of CPU resources or memory.

CVSS3: 6.5
nvd
больше 8 лет назад

Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-service attack caused by exponential XML entity expansion. The attack can cause the targeted process to consume an excessive amount of CPU resources or memory.

CVSS3: 6.5
debian
больше 8 лет назад

Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 throu ...

suse-cvrf
около 9 лет назад

Security update for subversion

CVSS3: 6.5
github
больше 3 лет назад

Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-service attack caused by exponential XML entity expansion. The attack can cause the targeted process to consume an excessive amount of CPU resources or memory.

4.4 Medium

CVSS3

3.5 Low

CVSS2