CVE-2009-1955
08.06.2009, 01:00
The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, as demonstrated by a PROPFIND request, a similar issue to CVE-2003-1564.
Vendor | Product | Version |
---|---|---|
apache | apr-util | 𝑥 < 1.3.7 |
apple | mac_os_x | 𝑥 < 10.6.2 |
debian | debian_linux | 4.0 |
canonical | ubuntu_linux | 6.06 |
canonical | ubuntu_linux | 8.04 |
canonical | ubuntu_linux | 8.10 |
canonical | ubuntu_linux | 9.04 |
oracle | http_server | - |
apache | http_server | 2.2.0 ≤ 𝑥 < 2.2.12 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References