Total vulnerabilities in the database
The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, as demonstrated by a PROPFIND request, a similar issue to CVE-2003-1564.
Software | From | Fixed in |
---|---|---|
apache / apr-util | - | 1.3.7 |
apple / mac_os_x | - | 10.6.2 |
suse / linux_enterprise_server | 9 | 9.x |
debian / debian_linux | 4.0 | 4.0.x |
canonical / ubuntu_linux | 9.04 | 9.04.x |
canonical / ubuntu_linux | 8.10 | 8.10.x |
canonical / ubuntu_linux | 8.04 | 8.04.x |
canonical / ubuntu_linux | 6.06 | 6.06.x |
fedoraproject / fedora | 11 | 11.x |
fedoraproject / fedora | 10 | 10.x |
fedoraproject / fedora | 9 | 9.x |
apache / http_server | 2.2.0 | 2.2.12 |