CVE-2007-1349

Publication date 30 March 2007

Last updated 24 July 2024


Ubuntu priority

PerlRun.pm in Apache mod_perl before 1.30, and RegistryCooker.pm in mod_perl 2.x, does not properly escape PATH_INFO before use in a regular expression, which allows remote attackers to cause a denial of service (resource consumption) via a crafted URI.

Status

Package Ubuntu Release Status
libapache2-mod-perl2 7.04 feisty
Fixed 2.0.2-2.3ubuntu1
6.10 edgy
Fixed 2.0.2-2ubuntu1.6.10.1
6.06 LTS dapper
Fixed 2.0.2-2ubuntu1.6.06.1

References

Related Ubuntu Security Notices (USN)

    • USN-488-1
    • mod_perl vulnerability
    • 18 July 2007

Other references