Subject: Bug#655435: libapr1: apr_hash vulnerable to oCert-2011-003 style DOS attacks Fixed in 1.4.6 If we need to backport in the future, the changes are located in only two files: tables/apr_hash.c test/testhash.c Attached patch was taken from upstream trunk, it can also apply to previous versions, including 1.4.2-6+squeeze3 |