CVE-2007-1349
Published: 30 March 2007
PerlRun.pm in Apache mod_perl before 1.30, and RegistryCooker.pm in mod_perl 2.x, does not properly escape PATH_INFO before use in a regular expression, which allows remote attackers to cause a denial of service (resource consumption) via a crafted URI.
Priority
Status
Package | Release | Status |
---|---|---|
libapache2-mod-perl2 Launchpad, Ubuntu, Debian |
dapper |
Released
(2.0.2-2ubuntu1.6.06.1)
|
edgy |
Released
(2.0.2-2ubuntu1.6.10.1)
|
|
feisty |
Released
(2.0.2-2.3ubuntu1)
|
|
upstream |
Needs triage
|