CVE-2007-1349
medium · 5PerlRun.pm in Apache mod_perl before 1.30, and RegistryCooker.pm in mod_perl 2.x, does not properly escape PATH_INFO before use in a regular expression, which allows remote attackers to cause a denial of service (resource consumption) via a crafted URI.
5
CVSS
10.1%
EPSS (exploit prob.)
95th
EPSS percentile
2007-03-30
Published
AV:N/AC:L/Au:N/C:N/I:N/A:P
Weaknesses
CWE-20
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apache | mod_perl | < 1.30 |
| apache | mod_perl | >= 2.0.0, <= 2.0.11 |
| canonical | ubuntu_linux | 6.06 |
| canonical | ubuntu_linux | 6.10 |
| canonical | ubuntu_linux | 7.04 |
| redhat | satellite | 5.1 |
| redhat | enterprise_linux_desktop | 3.0 |
| redhat | enterprise_linux_desktop | 4.0 |
| redhat | enterprise_linux_desktop | 5.0 |
| redhat | enterprise_linux_eus | 4.5 |
| redhat | enterprise_linux_server | 3.0 |
| redhat | enterprise_linux_server | 4.0 |
| redhat | enterprise_linux_server | 5.0 |
| redhat | enterprise_linux_workstation | 3.0 |
| redhat | enterprise_linux_workstation | 4.0 |
| redhat | enterprise_linux_workstation | 5.0 |
Check a specific version with /api/v1/cve/match.
References
- ftp://patches.sgi.com/support/free/security/advisories/20070602-01-P.asc
- http://rhn.redhat.com/errata/RHSA-2007-0395.html
- http://rhn.redhat.com/errata/RHSA-2008-0630.html
- http://secunia.com/advisories/24678
- http://secunia.com/advisories/24839
- http://secunia.com/advisories/25072
- http://secunia.com/advisories/25110
- http://secunia.com/advisories/25432
- http://secunia.com/advisories/25655
- http://secunia.com/advisories/25730
- http://secunia.com/advisories/25894
- http://secunia.com/advisories/26084
- http://secunia.com/advisories/26231
- http://secunia.com/advisories/26290
- http://secunia.com/advisories/31490
- http://secunia.com/advisories/31493
- http://secunia.com/advisories/33720
- http://secunia.com/advisories/33723
- http://security.gentoo.org/glsa/glsa-200705-04.xml
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-248386-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021508.1-1
- http://support.avaya.com/elmodocs2/security/ASA-2007-293.htm
- http://svn.apache.org/repos/asf/perl/modperl/branches/1.x/Changes
- http://www.gossamer-threads.com/lists/modperl/modperl/92739
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:083
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2007-1349