Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 272444 - dev-libs/apr-util <= 1.3.4 DoS through XML parser (CVE requested)
Summary: dev-libs/apr-util <= 1.3.4 DoS through XML parser (CVE requested)
Status: RESOLVED DUPLICATE of bug 272260
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://milw0rm.com/exploits/8842
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2009-06-03 15:18 UTC by Hanno Böck
Modified: 2009-06-03 16:50 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Hanno Böck gentoo-dev 2009-06-03 15:18:34 UTC
apr-util is vulnerable to an xml entity bomb, this affects e.g. mod_webdav/svn in apache.

See
http://milw0rm.com/exploits/8842 
http://svn.apache.org/viewvc?rev=781403&view=rev

CVE is requested on oss-security.
Comment 1 Alex Legler (RETIRED) archtester gentoo-dev Security 2009-06-03 16:50:54 UTC

*** This bug has been marked as a duplicate of bug 272260 ***