URL regular expression DoS (CVE-2007-1349)
A flaw was discovered in the Apache::PerlRun module shipped with mod_perl 1.29 and earlier and in the ModPerl::RegistryCooker module shipped with mod_perl 2.03 and earlier. A remote attacker could craft a URL with a path that would be interpreted as a regular expression, potentially allowing a denial of service by creating an expression that will take a very long time to run. This vulnerability only affects Apache::PerlRun and custom subclasses of ModPerl::RegistryCooker that explicitly use the namespace_from_uri() method. The Apache::Registry, ModPerl::PerlRun, and ModPerl::Registry modules are NOT affected.

Users of mod_perl 1.29 and earlier are encouraged to upgrade to 1.30 if they use Apache::PerlRun for their applications. Users of mod_perl 2.03 are encouraged to check their custom code for calls to the namespace_from_uri() method and replace it with the namespace_from_filename() method.

Please note!
mod_perl-1.24_01.tar.gz or later is required for Apache >= 1.3.14.

[ICO]NameLast modifiedSizeDescription

[DIR]Parent Directory  -  
[   ]KEYS03-Feb-2011 14:36 39K 
[   ]README01-Aug-2002 20:53 4.3K 
[   ]mod_perl-1.31.tar.gz12-May-2009 21:32 381K 
[   ]mod_perl-1.31.tar.gz.asc12-May-2009 21:32 194  
[DIR]mod_perl-1.31/11-May-2009 21:04 -  
[   ]mod_perl-2.0.5.tar.gz07-Feb-2011 17:35 3.6M 
[   ]mod_perl-2.0.5.tar.gz.asc07-Feb-2011 17:35 487  
[DIR]mod_perl-2.0.5/07-Feb-2011 16:13 -  
[   ]mod_perl-2.0.6.tar.gz25-Apr-2012 10:34 3.6M 
[   ]mod_perl-2.0.6.tar.gz.asc25-Apr-2012 10:34 495  
[DIR]mod_perl-2.0.6/25-Apr-2012 00:31 -