John Lightsey
2012-Jan-11 03:55 UTC
[Secure-testing-team] Bug#655435: libapr1: apr_hash vulnerable to oCert-2011-003 style DOS attacks
Package: libapr1 Version: 1.4.5-1.1 Severity: important Tags: security APR''s hash implementation is vulnerable to the same types of algorithmic complexity attacks disclosed in oCert-2011-003. Discussion of the problem on the apr-dev mailing list is available here: http://www.mail-archive.com/dev%40apr.apache.org/msg24439.html -- System Information: Debian Release: wheezy/sid APT prefers unstable APT policy: (500, ''unstable'') Architecture: amd64 (x86_64) Kernel: Linux 3.1.0-1-amd64 (SMP w/4 CPU cores) Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8) Shell: /bin/sh linked to /bin/dash Versions of packages libapr1 depends on: ii libc6 2.13-24 ii libuuid1 2.20.1-1.1 libapr1 recommends no packages. libapr1 suggests no packages. -- no debconf information