Release date:
Updated on:
Affected Systems:
Apache Group Sling 2.x
Description:
--------------------------------------------------------------------------------
Cve id: CVE-2012-2138
Apache Sling is an open-source Web framework on the Java platform. It creates content-oriented applications on the JCR content library.
In Apache Sling 2.1.2 and earlier versions, an input verification error exists when processing the @ CopyFrom operation in the Sling POST program. Specially crafted HTTP requests can be exploited to create infinite loops and consume memory and storage resources.
<* Source: Aaron T. Myers
Link: http://secunia.com/advisories/49840/
Https://issues.apache.org/jira/browse/SLING-2517
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://httpd.apache.org/