PT-2009-6720 · Apache+1 · Apr-Util+3

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2009-2412

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions APR versions 0.9.x through 1.3.x APR-util versions 0.9.x through 1.3.x
Description The issue is related to multiple integer overflows in the Apache Portable Runtime (APR) library and the Apache Portable Utility library (APR-util). These overflows can be triggered by crafted calls to functions such as allocator alloc or apr palloc in APR, and apr rmm malloc, apr rmm calloc, or apr rmm realloc in APR-util, potentially leading to buffer overflows. This could allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code. The vulnerability can be exploited remotely and may lead to a violation of confidentiality, integrity, and availability of protected information.
Recommendations For APR versions 0.9.x through 1.3.x, consider disabling the apr palloc() function until a patch is available. For APR-util versions 0.9.x through 1.3.x, restrict access to the apr rmm malloc, apr rmm calloc, and apr rmm realloc functions to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-03655
BDU:2015-03656
BDU:2015-03657
CVE-2009-2412
DSA-1854-1
OPENSUSE-SU-2024:10063-1
OPENSUSE-SU-2024:10268-1
OPENSUSE-SU-2024:10568-1
OPENSUSE-SU-2024:11586-1
OPENSUSE-SU-2024:11596-1
RHSA-2009:1204
RHSA-2009:1205
RHSA-2009:1462
RHSA-2009_1204
RHSA-2010:0602

Affected Products

Apr
Apr-Util
Apache Http Server
Red Hat