Lucene search

K
redhatcveRedhat.comRH:CVE-2016-8734
HistoryNov 29, 2016 - 11:47 p.m.

CVE-2016-8734

2016-11-2923:47:25
redhat.com
access.redhat.com
12

0.004 Low

EPSS

Percentile

73.2%

Apache Subversion’s mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-service attack caused by exponential XML entity expansion. The attack can cause the targeted process to consume an excessive amount of CPU resources or memory.

Mitigation

Only Apache+Subversion servers that have the "DontDoThatConfigFile" configuration option present are affected by this flaw. This option is not enabled in default httpd or mod_dav_svn configuration as shipped with Red Hat Enterprise Linux.