SB2017020664 - Amazon Linux AMI update for subversion, mod_dav_svn



SB2017020664 - Amazon Linux AMI update for subversion, mod_dav_svn

Published: February 6, 2017

Security Bulletin ID SB2017020664
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Resource exhaustion (CVE-ID: CVE-2016-8734)

The vulnerability allows a remote authenticated user to perform a denial of service (DoS) attack.

Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-service attack caused by exponential XML entity expansion. The attack can cause the targeted process to consume an excessive amount of CPU resources or memory.


Remediation

Install update from vendor's website.