Candidate: CVE-2016-2146 PublicDate: 2016-04-15 14:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2146 https://bugzilla.redhat.com/show_bug.cgi?id=1315747 Description: The am_read_post_data function in mod_auth_mellon before 0.11.1 does not limit the amount of data read, which allows remote attackers to cause a denial of service (worker process crash, web server deadlock, or memory consumption) via a large amount of POST data. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_libapache2-mod-auth-mellon: upstream: https://github.com/UNINETT/mod_auth_mellon/commit/ccb7dc35b941667122e02d5e81a52e2e4718ccee upstream_libapache2-mod-auth-mellon: released (0.12.0-1) precise_libapache2-mod-auth-mellon: DNE precise/esm_libapache2-mod-auth-mellon: DNE trusty_libapache2-mod-auth-mellon: ignored (reached end-of-life) trusty/esm_libapache2-mod-auth-mellon: DNE (trusty was needed) vivid/stable-phone-overlay_libapache2-mod-auth-mellon: DNE vivid/ubuntu-core_libapache2-mod-auth-mellon: DNE wily_libapache2-mod-auth-mellon: ignored (reached end-of-life) xenial_libapache2-mod-auth-mellon: not-affected (0.12.0-1) yakkety_libapache2-mod-auth-mellon: not-affected (0.12.0-1) zesty_libapache2-mod-auth-mellon: not-affected (0.12.0-1) artful_libapache2-mod-auth-mellon: not-affected (0.12.0-1) bionic_libapache2-mod-auth-mellon: not-affected (0.12.0-1) cosmic_libapache2-mod-auth-mellon: not-affected (0.12.0-1) disco_libapache2-mod-auth-mellon: not-affected (0.12.0-1) devel_libapache2-mod-auth-mellon: not-affected (0.12.0-1)