LWN.net Logo

apr-util: denial of service

Package(s):apr-util CVE #(s):CVE-2009-0023
Created:June 5, 2009 Updated:December 4, 2009
Description: From the Debian advisory:

"kcope" discovered a flaw in the handling of internal XML entities in the apr_xml_* interface that can be exploited to use all available memory. This denial of service can be triggered remotely in the Apache mod_dav and mod_dav_svn modules. (No CVE id yet)

Matthew Palmer discovered an underflow flaw in the apr_strmatch_precompile function that can be exploited to cause a daemon crash. The vulnerability can be triggered (1) remotely in mod_dav_svn for Apache if the "SVNMasterURI"directive is in use, (2) remotely in mod_apreq2 for Apache or other applications using libapreq2, or (3) locally in Apache by a crafted ".htaccess" file. (CVE-2009-0023)

Alerts:
Mandriva MDVSA-2009:314 2009-12-04
SuSE SUSE-SR:2009:013 2009-08-11
Slackware SSA:2009-214-01 2009-08-03
Gentoo 200907-03 2009-07-04
Fedora FEDORA-2009-6261 2009-06-15
Fedora FEDORA-2009-5969 2009-06-15
Fedora FEDORA-2009-6014 2009-06-15
CentOS CESA-2009:1107 2009-06-19
Red Hat RHSA-2009:1108-01 2009-06-16
Red Hat RHSA-2009:1107-01 2009-06-16
Slackware SSA:2009-167-02 2009-06-17
CentOS CESA-2009:1108 2009-06-17
Ubuntu USN-787-1 2009-06-12
Ubuntu USN-786-1 2009-06-10
Mandriva MDVSA-2009:131-1 2009-06-06
Mandriva MDVSA-2009:131 2009-06-06
Debian DSA-1812-1 2009-06-04
rPath rPSA-2009-0144-1 2009-11-12

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds