PT-2009-2738 · Apache+1 · Apache Http Server+5

Published

2009-06-01

·

Updated

2024-06-15

·

CVE-2009-0023

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Apache APR-util versions prior to 1.3.5
Description The issue allows remote attackers to cause a denial of service (daemon crash) via crafted input involving a .htaccess file used with the Apache HTTP Server, the SVNMasterURI directive in the mod dav svn module in the Apache HTTP Server, the mod apreq2 module for the Apache HTTP Server, or an application that uses the libapreq2 library, which triggers a heap-based buffer underflow. A heap-based underwrite flaw was found in the way the bundled copy of the APR-util library created compiled forms of particular search patterns. An attacker could formulate a specially-crafted search keyword, that would overwrite arbitrary heap memory locations when processed by the pattern preparation engine.
Recommendations For Apache APR-util versions prior to 1.3.5, update to version 1.3.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the apr strmatch precompile function until a patch is available. Avoid using crafted search keywords in applications that utilize the libapreq2 library until the issue is resolved.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-0023
DSA-1812-1
HPSBUX02612
OPENSUSE-SU-2024:10268-1
OPENSUSE-SU-2024:10568-1
OPENSUSE-SU-2024:11586-1
RHSA-2009:1107
RHSA-2009:1108
RHSA-2009:1160
RHSA-2009_1107
RHSA-2010:0602

Affected Products

Apache Apr-Util
Apache Http Server
Red Hat
Libapreq2
Mod Apreq2
Mod Dav Svn