Lucene search

K
ubuntucveUbuntu.comUB:CVE-2016-8734
HistoryNov 30, 2016 - 12:00 a.m.

CVE-2016-8734

2016-11-3000:00:00
ubuntu.com
ubuntu.com
12

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:N/A:P

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS

0.004

Percentile

73.1%

Apache Subversion’s mod_dontdothat module and HTTP clients 1.4.0 through
1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-service
attack caused by exponential XML entity expansion. The attack can cause the
targeted process to consume an excessive amount of CPU resources or memory.

Notes

Author Note
mdeslaur for mod_dontdothat, we don’t ship it in binary packages for clients, we build with serf, so we’re vulnerable
OSVersionArchitecturePackageVersionFilename
ubuntu14.04noarchsubversion< 1.8.8-1ubuntu3.3UNKNOWN
ubuntu16.04noarchsubversion< 1.9.3-2ubuntu1.1UNKNOWN

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:N/A:P

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS

0.004

Percentile

73.1%