imPC@ndo IT

Tracker / CVE-2009-1955

CVE-2009-1955

High 7.5

The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, as demonstrated by a PROPFIND request, a similar issue to CVE-2003-1564.

Affected products and versions

apache apr-util · … → 1.3.7
apache http_server · 2.2.0 → 2.2.12
apple mac_os_x · … → 10.6.2
canonical ubuntu_linux
debian debian_linux
fedoraproject fedora
oracle http_server
suse linux_enterprise_server

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References