CVE-2009-1956
08.06.2009, 01:00
Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via crafted input.Enginsight
Vendor | Product | Version |
---|---|---|
apache | apr-util | 𝑥 ≤ 1.3.4 |
apache | http_server | 2.2.0 ≤ 𝑥 < 2.2.12 |
canonical | ubuntu_linux | 6.06 |
canonical | ubuntu_linux | 8.04 |
canonical | ubuntu_linux | 8.10 |
canonical | ubuntu_linux | 9.04 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References