The CGI scripts in (1) LedgerSMB (LSMB) before 1.2.15 and (2) SQL-Ledger 2.8.17 and earlier allow remote attackers to cause a denial of service (resource exhaustion) via an HTTP POST request with a large Content-Length.
- http://securityreason.com/securityalert/4250
- https://github.com/fkie-cad/nvd-json-data-feeds