Posted by Eric Covener on Oct 01 Severity: moderate Affected versions: - Apache HTTP Server through 2.4.68 Description: Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XML namespaces. Credit: Zhen Kong (finder) Calif.io in collaboration with Anthropic (finder) AISLE in...

Read the full article at oss-security →