Описание
ViewVC before 1.1.11 allows remote attackers to bypass the cvsdb row_limit configuration setting, and consequently conduct resource-consumption attacks, via the limit parameter, as demonstrated by a "query revision history" request.
Релиз | Статус | Примечание |
---|---|---|
dapper | DNE | |
devel | not-affected | |
esm-apps/xenial | not-affected | |
esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was not-affected] |
hardy | ignored | end of life |
lucid | ignored | end of life |
maverick | ignored | end of life |
natty | ignored | end of life |
oneiric | ignored | end of life |
precise | released | 1.1.5-1.1+squeeze2build0.12.04.1 |
Показывать по
Ссылки на источники
5 Medium
CVSS2
Связанные уязвимости
ViewVC before 1.1.11 allows remote attackers to bypass the cvsdb row_limit configuration setting, and consequently conduct resource-consumption attacks, via the limit parameter, as demonstrated by a "query revision history" request.
ViewVC before 1.1.11 allows remote attackers to bypass the cvsdb row_l ...
ViewVC before 1.1.11 allows remote attackers to bypass the cvsdb row_limit configuration setting, and consequently conduct resource-consumption attacks, via the limit parameter, as demonstrated by a "query revision history" request.
Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность защищаемой информации
5 Medium
CVSS2