GCVE-VVD-MAGEIA-2017-9
Advisory Published
Vulnetix · Advisory published February 26, 2017
Subversion's mod_dontdothat module and clients using http(s):// are vulnerable to a denial-of-service attack caused by exponential XML entity expansion. The attack, otherwise known as the "billion laughs attack", targets XML parsers and can cause the targeted process to consume an excessive amount of CPU resources or memory (CVE-2016-8734).

Affected Products

VendorProductVersionsPlatforms
Mageiamailman0 (affected), 2.1.20-3.1.mga5 (unaffected)
Mageiasubversion0 (affected), 1.8.17-1.mga5 (unaffected), 0 (affected), 1.8.17-1.mga5 (unaffected)

References

Browse GCVE Records

100 records in the GCVE database · Updated April 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.