|
|
| |
|
| |
apr-util: denial of service
| Package(s): | apr-util |
CVE #(s): | CVE-2009-0023
|
| Created: | June 5, 2009 |
Updated: | December 4, 2009 |
| Description: |
From the Debian advisory:
"kcope" discovered a flaw in the handling of internal XML entities in
the apr_xml_* interface that can be exploited to use all available
memory. This denial of service can be triggered remotely in the Apache
mod_dav and mod_dav_svn modules. (No CVE id yet)
Matthew Palmer discovered an underflow flaw in the
apr_strmatch_precompile function that can be exploited to cause a
daemon crash. The vulnerability can be triggered (1) remotely in
mod_dav_svn for Apache if the "SVNMasterURI"directive is in use, (2)
remotely in mod_apreq2 for Apache or other applications using
libapreq2, or (3) locally in Apache by a crafted ".htaccess" file.
(CVE-2009-0023)
|
| Alerts: |
|
( Log in to post comments)
|
|
|