|
|
Log in / Subscribe / Register

mod_perl: denial of service

Package(s):mod_perl CVE #(s):CVE-2007-1349
Created:April 12, 2007 Updated:July 18, 2007
Description: Apache mod_perl versions 1.30 and below have a vulnerability in PerlRun.pm and RegistryCooker.pm. PATH_INFO is not properly escaped before use in a regular expression, allowing remote attackers to cause a denial of service via a specially crafted URI.
Alerts:
Ubuntu USN-488-1 libapache2-mod-perl2 2007-07-17
Red Hat RHSA-2007:0396-02 mod_perl 2007-06-20
Red Hat RHSA-2007:0486-01 mod_perl 2007-06-18
Red Hat RHSA-2007:0395-01 mod_perl 2007-06-14
Fedora FEDORA-2007-577 mod_perl 2007-06-11
Fedora FEDORA-2007-576 mod_perl 2007-06-11
Fedora FEDORA-2007-0316 mod_perl 2007-06-09
OpenPKG OpenPKG-SA-2007.011 apache 2007-05-18
Gentoo 200705-04 mod_perl 2007-05-02
Mandriva MDKSA-2007:083 apache-mod_perl 2007-04-11

The LWN site is currently under high scraper load, so comment display has been suppressed for anonymous users. If you are a human, you may read the comments by clicking the button below:

Note: you can avoid this step in the future by logging into your LWN account.


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds