PT-2009-2738 · Apache+1 · Apache Http Server+5
Published
2009-06-01
·
Updated
2024-06-15
·
CVE-2009-0023
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Apache APR-util versions prior to 1.3.5
Description
The issue allows remote attackers to cause a denial of service (daemon crash) via crafted input involving a .htaccess file used with the Apache HTTP Server, the SVNMasterURI directive in the mod dav svn module in the Apache HTTP Server, the mod apreq2 module for the Apache HTTP Server, or an application that uses the libapreq2 library, which triggers a heap-based buffer underflow. A heap-based underwrite flaw was found in the way the bundled copy of the APR-util library created compiled forms of particular search patterns. An attacker could formulate a specially-crafted search keyword, that would overwrite arbitrary heap memory locations when processed by the pattern preparation engine.
Recommendations
For Apache APR-util versions prior to 1.3.5, update to version 1.3.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the
apr strmatch precompile function until a patch is available. Avoid using crafted search keywords in applications that utilize the libapreq2 library until the issue is resolved.Fix
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Apr-Util
Apache Http Server
Red Hat
Libapreq2
Mod Apreq2
Mod Dav Svn