PT-2016-7558 · Apache+3 · Apache Subversion+3
Publicado
2016-11-30
·
Atualizado
2024-06-15
·
CVE-2016-8734
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Apache Subversion versions 1.4.0 through 1.8.16
Apache Subversion versions 1.9.0 through 1.9.4
Description
The issue is caused by exponential XML entity expansion, which can lead to a denial-of-service attack. This attack can cause the targeted process to consume an excessive amount of CPU resources or memory.
Recommendations
For versions 1.4.0 through 1.8.16, update to a version outside of this range to mitigate the risk.
For versions 1.9.0 through 1.9.4, update to a version outside of this range to mitigate the risk.
As a temporary workaround, consider restricting the use of the mod dontdothat module until a patch is available.
Correção
DoS
Resource Exhaustion
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Apache Subversion
Suse
Ubuntu