Bug 1280 - CVE-2011-0419, ressource exhaustion
Summary: CVE-2011-0419, ressource exhaustion
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: i586 Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Mageia Bug Squad
QA Contact:
URL:
Whiteboard:
Keywords:
Depends on:
Blocks: 908
  Show dependency treegraph
 
Reported: 2011-05-15 02:14 CEST by Michael Scherer
Modified: 2011-05-15 02:26 CEST (History)
1 user (show)

See Also:
Source RPM: apr
CVE:
Status comment:


Attachments

Description Michael Scherer 2011-05-15 02:14:54 CEST
http://lists.mandriva.com/security-announce/2011-05/msg00005.php


It was discovered that the apr_fnmatch() function used an unconstrained
 recursion when processing patterns with the '*' wildcard. An attacker
 could use this flaw to cause an application using this function,
 which also accepted untrusted input as a pattern for matching (such
 as an httpd server using the mod_autoindex module), to exhaust all
 stack memory or use an excessive amount of CPU time when performing
 matching (CVE-2011-0419).
Michael Scherer 2011-05-15 02:15:03 CEST

Blocks: (none) => 908

Comment 1 D Morgan 2011-05-15 02:26:15 CEST
Fixed in commit 98877.

Status: NEW => RESOLVED
CC: (none) => dmorganec
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.