INFORMATION

Name : CVE-2009-0023 First Publication : 2009-06-07
Severity : Medium Last Modification : 2010-08-21

SCORING CVSS v2

Cvss Base Score : 4.3 Attack Range : Network
Cvss Impact Score : 2.9 Attack Complexity : Medium
Cvss Expoit Score : 8.6 Authentification : None Required

Calculate full CVSS 2.0 Vectors scores

DETAIL

The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-util before 1.3.5 allows remote attackers to cause a denial of service (daemon crash) via crafted input involving (1) a .htaccess file used with the Apache HTTP Server, (2) the SVNMasterURI directive in the mod_dav_svn module in the Apache HTTP Server, (3) the mod_apreq2 module for the Apache HTTP Server, or (4) an application that uses the libapreq2 library, which triggers a heap-based buffer underflow.



CWE COMMON WEAKNESS ENUMERATION

OVALID

oval:org.mitre.oval:def:10968, The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-util before 1.3.5 allows remote attackers to cause a denial of service (daemon crash) via crafted input involving (1) a .htaccess file used with the Apache HTTP Server, (2) the

oval:org.mitre.oval:def:11782, The operating system installed on the system is Red Hat Enterprise Linux 3
oval:org.mitre.oval:def:11831, The operating system installed on the system is Red Hat Enterprise Linux 4
oval:org.mitre.oval:def:11414, The operating system installed on the system is Red Hat Enterprise Linux 5

CPE COMMON PLATFORM ENUMERATION

OPEN SOURCE VULNERABILTY DATABASE (OSVDB)

55059 : Apache APR-util strmatch/apr_strmatch.c apr_strmatch_precompile Function Crafted Input Remote DoS.


SECONDARY(S) SOURCE(S)


Source : AIXAPAR
Url : http://www-01.ibm.com/support/docview.wss?uid=swg1PK88341
Url : http://www-01.ibm.com/support/docview.wss?uid=swg1PK91241
Url : http://www-01.ibm.com/support/docview.wss?uid=swg1PK99478

Source : APPLE
Url : http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html

Source : BID
Url : http://www.securityfocus.com/bid/35221

Source : BUGTRAQ
Url : http://www.securityfocus.com/archive/1/archive/1/507855/100/0/threaded

Source : CONFIRM
Url : http://support.apple.com/kb/HT3937
Url : http://svn.apache.org/viewvc?view=rev&revision=779880
Url : http://wiki.rpath.com/Advisories:rPSA-2009-0144
Url : http://www-01.ibm.com/support/docview.wss?uid=swg27014463
Url : http://www.apache.org/dist/apr/CHANGES-APR-UTIL-1.3
Url : https://bugzilla.redhat.com/show_bug.cgi?id=503928

Source : DEBIAN
Url : http://www.debian.org/security/2009/dsa-1812

Source : FEDORA
Url : https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01173.html
Url : https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01201.html
Url : https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01228.html

Source : GENTOO
Url : http://security.gentoo.org/glsa/glsa-200907-03.xml

Source : MANDRIVA
Url : http://www.mandriva.com/security/advisories?name=MDVSA-2009:131

Source : REDHAT
Url : http://www.redhat.com/support/errata/RHSA-2009-1107.html
Url : http://www.redhat.com/support/errata/RHSA-2009-1108.html

Source : SECUNIA
Url : http://secunia.com/advisories/34724
Url : http://secunia.com/advisories/35284
Url : http://secunia.com/advisories/35360
Url : http://secunia.com/advisories/35395
Url : http://secunia.com/advisories/35444
Url : http://secunia.com/advisories/35487
Url : http://secunia.com/advisories/35565
Url : http://secunia.com/advisories/35710
Url : http://secunia.com/advisories/35797
Url : http://secunia.com/advisories/35843
Url : http://secunia.com/advisories/37221

Source : SLACKWARE
Url : http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.538210

Source : UBUNTU
Url : http://www.ubuntu.com/usn/usn-786-1
Url : http://www.ubuntu.com/usn/usn-787-1

Source : VUPEN
Url : http://www.vupen.com/english/advisories/2009/1907
Url : http://www.vupen.com/english/advisories/2009/3184

Source : XF
Url : http://xforce.iss.net/xforce/xfdb/50964