LWN.net Logo

mod_perl: denial of service

Package(s):mod_perl CVE #(s):CVE-2007-1349
Created:April 12, 2007 Updated:July 18, 2007
Description: Apache mod_perl versions 1.30 and below have a vulnerability in PerlRun.pm and RegistryCooker.pm. PATH_INFO is not properly escaped before use in a regular expression, allowing remote attackers to cause a denial of service via a specially crafted URI.
Alerts:
Ubuntu USN-488-1 2007-07-17
Red Hat RHSA-2007:0396-02 2007-06-20
Red Hat RHSA-2007:0486-01 2007-06-18
Red Hat RHSA-2007:0395-01 2007-06-14
Fedora FEDORA-2007-577 2007-06-11
Fedora FEDORA-2007-576 2007-06-11
Fedora FEDORA-2007-0316 2007-06-09
OpenPKG OpenPKG-SA-2007.011 2007-05-18
Gentoo 200705-04 2007-05-02
Mandriva MDKSA-2007:083 2007-04-11

(Log in to post comments)

mod_perl: denial of service

Posted Jun 21, 2007 9:46 UTC (Thu) by mjcox@redhat.com (subscriber, #31775) [Link]

Mandriva MDKSA-2007:083 2006-04-11
should probably be
Mandriva MDKSA-2007:083 2007-04-11

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds