PT-2009-2738 · Apache+1 · Apache Http Server+5

Publicado

2009-06-01

·

Atualizado

2024-06-15

·

CVE-2009-0023

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Apache APR-util versions prior to 1.3.5
Description The issue allows remote attackers to cause a denial of service (daemon crash) via crafted input involving a .htaccess file used with the Apache HTTP Server, the SVNMasterURI directive in the mod dav svn module in the Apache HTTP Server, the mod apreq2 module for the Apache HTTP Server, or an application that uses the libapreq2 library, which triggers a heap-based buffer underflow. A heap-based underwrite flaw was found in the way the bundled copy of the APR-util library created compiled forms of particular search patterns. An attacker could formulate a specially-crafted search keyword, that would overwrite arbitrary heap memory locations when processed by the pattern preparation engine.
Recommendations For Apache APR-util versions prior to 1.3.5, update to version 1.3.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the apr strmatch precompile function until a patch is available. Avoid using crafted search keywords in applications that utilize the libapreq2 library until the issue is resolved.

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-0023
DSA-1812-1
HPSBUX02612
OPENSUSE-SU-2024:10268-1
OPENSUSE-SU-2024:10568-1
OPENSUSE-SU-2024:11586-1
RHSA-2009:1107
RHSA-2009:1108
RHSA-2009:1160
RHSA-2009_1107
RHSA-2010:0602

Produtos afetados

Apache Apr-Util
Apache Http Server
Red Hat
Libapreq2
Mod Apreq2
Mod Dav Svn