PT-2016-7558 · Apache+3 · Apache Subversion+3

Published

2016-11-30

·

Updated

2024-06-15

·

CVE-2016-8734

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apache Subversion versions 1.4.0 through 1.8.16 Apache Subversion versions 1.9.0 through 1.9.4
Description The issue is caused by exponential XML entity expansion, which can lead to a denial-of-service attack. This attack can cause the targeted process to consume an excessive amount of CPU resources or memory.
Recommendations For versions 1.4.0 through 1.8.16, update to a version outside of this range to mitigate the risk. For versions 1.9.0 through 1.9.4, update to a version outside of this range to mitigate the risk. As a temporary workaround, consider restricting the use of the mod dontdothat module until a patch is available.

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-1641
ALT-PU-2020-2914
CVE-2016-8734
DSA-3932-1
MGASA-2017-0009
OPENSUSE-SU-2024:10538-1
SUSE-SU-2017:2163-1
SUSE-SU-2017:2200-1
SUSE-SU-2017_2163-1
USN-3388-1

Affected Products

Alt Linux
Apache Subversion
Suse
Ubuntu