Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 272444

Summary: dev-libs/apr-util <= 1.3.4 DoS through XML parser (CVE requested)
Product: Gentoo Security Reporter: Hanno Böck <hanno>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED DUPLICATE    
Severity: normal CC: apache-bugs
Priority: High    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: http://milw0rm.com/exploits/8842
Whiteboard:
Package list:
Runtime testing required: ---

Description Hanno Böck gentoo-dev 2009-06-03 15:18:34 UTC
apr-util is vulnerable to an xml entity bomb, this affects e.g. mod_webdav/svn in apache.

See
http://milw0rm.com/exploits/8842 
http://svn.apache.org/viewvc?rev=781403&view=rev

CVE is requested on oss-security.
Comment 1 Alex Legler (RETIRED) archtester gentoo-dev Security 2009-06-03 16:50:54 UTC

*** This bug has been marked as a duplicate of bug 272260 ***