LWN.net Logo

mod_rpaf: denial of service

Package(s):mod_rpaf CVE #(s):CVE-2012-3526
Created:September 28, 2012 Updated:October 3, 2012
Description:

From the Gentoo advisory:

An error has been found in the way mod_rpaf handles X-Forwarded-For headers. Please review the CVE identifier referenced below for details.

A remote attacker could send a specially crafted HTTP header, possibly resulting in a Denial of Service condition.

Alerts:
Gentoo 201209-20 2012-09-27

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds