CVE-2007-1349

PerlRun.pm in Apache mod_perl before 1.30, and RegistryCooker.pm in mod_perl 2.x, does not properly escape PATH_INFO before use in a regular expression, which allows remote attackers to cause a denial of service (resource consumption) via a crafted URI.

Date published : 2007-03-29

http://www.securityfocus.com/bid/23192

http://support.avaya.com/elmodocs2/security/ASA-2007-293.htm