Total vulnerabilities in the database
The am_read_post_data function in mod_auth_mellon before 0.11.1 does not limit the amount of data read, which allows remote attackers to cause a denial of service (worker process crash, web server deadlock, or memory consumption) via a large amount of POST data.
Software | From | Fixed in |
---|---|---|
fedoraproject / fedora | 23 | 23.x |
uninett / mod_auth_mellon | - | 0.11.0.x |