Bug 504555 (CVE-2009-1955)
Summary: | CVE-2009-1955 apr-util billion laughs attack | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Mark J. Cox <mjc> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | bojan, bressers, jorton, kreilly |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-1955 | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2012-06-20 17:10:29 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 504558, 504559, 504560, 504561, 504562, 505026, 505027, 591930, 595829 | ||
Bug Blocks: |
Description
Mark J. Cox
2009-06-08 08:15:07 UTC
*** Bug 503814 has been marked as a duplicate of this bug. *** Public exploit posted to milw0rm: http://www.milw0rm.com/exploits/8842 Upstream patch: http://svn.apache.org/viewvc?view=rev&revision=781403 http://marc.info/?l=apr-dev&m=124396021826125&w=2 Note that the patch committed is different from the one posted to the list. This issue has been addressed in following products: Red Hat Enterprise Linux 3 Via RHSA-2009:1108 https://rhn.redhat.com/errata/RHSA-2009-1108.html This issue has been addressed in following products: Red Hat Enterprise Linux 5 Red Hat Enterprise Linux 4 Via RHSA-2009:1107 https://rhn.redhat.com/errata/RHSA-2009-1107.html apr-util-1.2.12-7.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report. apr-util-1.3.7-1.fc11 has been pushed to the Fedora 11 stable repository. If problems still persist, please make note of it in this bug report. apr-util-1.3.7-1.fc10 has been pushed to the Fedora 10 stable repository. If problems still persist, please make note of it in this bug report. This issue has been addressed in following products: JBEWS 1.0.0 for RHEL 4 Via RHSA-2009:1160 https://rhn.redhat.com/errata/RHSA-2009-1160.html This issue has been addressed in following products: Red Hat Certificate System 7.3 Via RHSA-2010:0602 https://rhn.redhat.com/errata/RHSA-2010-0602.html |