URL regular expression DoS (CVE-2007-1349)
A flaw was discovered in the Apache::PerlRun module shipped with
mod_perl 1.29 and earlier and in the ModPerl::RegistryCooker module shipped with
mod_perl 2.03 and earlier. A remote attacker could craft a URL with a path that
would be interpreted as a regular expression, potentially allowing a
denial of service by creating an expression that will take a very long
time to run. This vulnerability only affects Apache::PerlRun and
custom subclasses of ModPerl::RegistryCooker that explicitly use the
namespace_from_uri() method. The Apache::Registry, ModPerl::PerlRun,
and ModPerl::Registry modules are NOT affected.
Users of mod_perl 1.29 and earlier are encouraged to upgrade to 1.30 if they use Apache::PerlRun for their applications. Users of mod_perl 2.03 are encouraged to check their custom code for calls to the namespace_from_uri() method and replace it with the namespace_from_filename() method.
Please note!
mod_perl-1.24_01.tar.gz or later is required for Apache >= 1.3.14.
| Name | Last modified | Size | Description | |
|---|---|---|---|---|
| Parent Directory | - | |||
| KEYS | 03-Feb-2011 14:36 | 39K | ||
| README | 01-Aug-2002 20:53 | 4.3K | ||
| mod_perl-1.31.tar.gz | 12-May-2009 21:32 | 381K | ||
| mod_perl-1.31/ | 11-May-2009 21:04 | - | ||
| mod_perl-2.0.6.tar.gz | 25-Apr-2012 10:34 | 3.6M | ||
| mod_perl-2.0.7.tar.gz | 05-Jun-2012 21:42 | 3.6M | ||
| mod_perl-2.0.7/ | 05-Jun-2012 21:18 | - | ||
| mod_perl-2.0.8.tar.gz | 17-Apr-2013 21:13 | 3.6M | ||
| mod_perl-2.0.8/ | 17-Apr-2013 20:59 | - | ||