Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-8734

Опубликовано: 29 нояб. 2016
Источник: redhat
CVSS3: 4.4
CVSS2: 3.5
EPSS Низкий

Описание

Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-service attack caused by exponential XML entity expansion. The attack can cause the targeted process to consume an excessive amount of CPU resources or memory.

Меры по смягчению последствий

Only Apache+Subversion servers that have the "DontDoThatConfigFile" configuration option present are affected by this flaw. This option is not enabled in default httpd or mod_dav_svn configuration as shipped with Red Hat Enterprise Linux.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5subversionNot affected
Red Hat Enterprise Linux 6subversionNot affected
Red Hat Enterprise Linux 7subversionWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-776
https://bugzilla.redhat.com/show_bug.cgi?id=1397403subversion: unrestricted XML entity expansion in mod_dontdothat and Subversion clients using http(s)://

EPSS

Процентиль: 93%
0.0638
Низкий

4.4 Medium

CVSS3

3.5 Low

CVSS2

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 9 лет назад

Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-service attack caused by exponential XML entity expansion. The attack can cause the targeted process to consume an excessive amount of CPU resources or memory.

CVSS3: 6.5
nvd
почти 9 лет назад

Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-service attack caused by exponential XML entity expansion. The attack can cause the targeted process to consume an excessive amount of CPU resources or memory.

CVSS3: 6.5
debian
почти 9 лет назад

Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 throu ...

suse-cvrf
больше 9 лет назад

Security update for subversion

CVSS3: 6.5
github
больше 4 лет назад

Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-service attack caused by exponential XML entity expansion. The attack can cause the targeted process to consume an excessive amount of CPU resources or memory.

EPSS

Процентиль: 93%
0.0638
Низкий

4.4 Medium

CVSS3

3.5 Low

CVSS2