URL regular expression DoS (CVE-2007-1349)
A flaw was discovered in the Apache::PerlRun module shipped with mod_perl 1.29 and earlier and in the ModPerl::RegistryCooker module shipped with mod_perl 2.03 and earlier. A remote attacker could craft a URL with a path that would be interpreted as a regular expression, potentially allowing a denial of service by creating an expression that will take a very long time to run. This vulnerability only affects Apache::PerlRun and custom subclasses of ModPerl::RegistryCooker that explicitly use the namespace_from_uri() method. The Apache::Registry, ModPerl::PerlRun, and ModPerl::Registry modules are NOT affected.

Users of mod_perl 1.29 and earlier are encouraged to upgrade to 1.30 if they use Apache::PerlRun for their applications. Users of mod_perl 2.03 are encouraged to check their custom code for calls to the namespace_from_uri() method and replace it with the namespace_from_filename() method.

Please note!
mod_perl-1.24_01.tar.gz or later is required for Apache >= 1.3.14.

Icon  Name                      Last modified      Size  Description
[DIR] Parent Directory - Perl project [DIR] mod_perl-1.31/ 11-May-2009 22:04 - Perl project [DIR] mod_perl-2.0.5/ 07-Feb-2011 17:13 - Perl project [DIR] mod_perl-2.0.6/ 25-Apr-2012 01:31 - Perl project [TXT] HEADER.html 30-Mar-2007 08:38 1.1K Perl project [SIG] KEYS 03-Feb-2011 15:36 39K Developer PGP/GPG keys [TXT] README 01-Aug-2002 21:53 4.3K Perl project [   ] mod_perl-1.31.tar.gz 12-May-2009 22:32 381K Perl project [SIG] mod_perl-1.31.tar.gz.asc 12-May-2009 22:32 194 PGP signature [   ] mod_perl-2.0.5.tar.gz 07-Feb-2011 18:35 3.6M Perl project [SIG] mod_perl-2.0.5.tar.gz.asc 07-Feb-2011 18:35 487 PGP signature [   ] mod_perl-2.0.6.tar.gz 25-Apr-2012 11:34 3.6M Perl project [SIG] mod_perl-2.0.6.tar.gz.asc 25-Apr-2012 11:34 495 PGP signature
Apache/2.2.3 (Scientific Linux) DAV/2 PHP/5.1.6 mod_python/3.2.8 Python/2.4.3 mod_ssl/2.2.3 OpenSSL/0.9.8e-fips-rhel5 mod_perl/2.0.4 Perl/v5.8.8 Server at apache.spinellicreations.com Port 80