PT-2016-7558 · Apache+3 · Apache Subversion+3
Published
2016-11-30
·
Updated
2024-06-15
·
CVE-2016-8734
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Apache Subversion versions 1.4.0 through 1.8.16
Apache Subversion versions 1.9.0 through 1.9.4
Description
The issue is caused by exponential XML entity expansion, which can lead to a denial-of-service attack. This attack can cause the targeted process to consume an excessive amount of CPU resources or memory.
Recommendations
For versions 1.4.0 through 1.8.16, update to a version outside of this range to mitigate the risk.
For versions 1.9.0 through 1.9.4, update to a version outside of this range to mitigate the risk.
As a temporary workaround, consider restricting the use of the mod dontdothat module until a patch is available.
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Apache Subversion
Suse
Ubuntu