INFORMATION

Name : CVE-2009-1955 First Publication : 2009-06-07
Severity : High Last Modification : 2010-08-21

SCORING CVSS v2

Cvss Base Score : 7.8 Attack Range : Network
Cvss Impact Score : 6.9 Attack Complexity : Low
Cvss Expoit Score : 10 Authentification : None Required

Calculate full CVSS 2.0 Vectors scores

DETAIL

The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, as demonstrated by a PROPFIND request, a similar issue to CVE-2003-1564.



CWE COMMON WEAKNESS ENUMERATION

OVALID

oval:org.mitre.oval:def:10270, The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via a cra

oval:org.mitre.oval:def:11782, The operating system installed on the system is Red Hat Enterprise Linux 3
oval:org.mitre.oval:def:11831, The operating system installed on the system is Red Hat Enterprise Linux 4
oval:org.mitre.oval:def:11414, The operating system installed on the system is Red Hat Enterprise Linux 5

CPE COMMON PLATFORM ENUMERATION

MILW0RM EXPLOITS

8842 : Apache mod_dav / svn Remote Denial of Service Exploit.

OPEN SOURCE VULNERABILTY DATABASE (OSVDB)

55057 : Apache APR-util xml/apr_xml.c apr_xml_* Interface Expat XML Parser Crafted XML Document Remote DoS.


SECONDARY(S) SOURCE(S)


Source : AIXAPAR
Url : http://www-01.ibm.com/support/docview.wss?uid=swg1PK88342
Url : http://www-01.ibm.com/support/docview.wss?uid=swg1PK91241
Url : http://www-01.ibm.com/support/docview.wss?uid=swg1PK99478

Source : APPLE
Url : http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html

Source : BID
Url : http://www.securityfocus.com/bid/35253

Source : BUGTRAQ
Url : http://www.securityfocus.com/archive/1/archive/1/506053/100/0/threaded

Source : CONFIRM
Url : http://support.apple.com/kb/HT3937
Url : http://svn.apache.org/viewvc?view=rev&revision=781403
Url : http://wiki.rpath.com/Advisories:rPSA-2009-0123
Url : http://www-01.ibm.com/support/docview.wss?uid=swg27014463
Url : http://www.apache.org/dist/apr/CHANGES-APR-UTIL-1.3

Source : DEBIAN
Url : http://www.debian.org/security/2009/dsa-1812

Source : FEDORA
Url : https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01173.html
Url : https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01201.html
Url : https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01228.html

Source : GENTOO
Url : http://security.gentoo.org/glsa/glsa-200907-03.xml

Source : MANDRIVA
Url : http://www.mandriva.com/security/advisories?name=MDVSA-2009:131

Source : MILW0RM
Url : http://www.milw0rm.com/exploits/8842

Source : MLIST
Url : http://marc.info/?l=apr-dev&m=124396021826125&w=2
Url : http://www.openwall.com/lists/oss-security/2009/06/03/4

Source : REDHAT
Url : http://www.redhat.com/support/errata/RHSA-2009-1107.html
Url : http://www.redhat.com/support/errata/RHSA-2009-1108.html

Source : SECUNIA
Url : http://secunia.com/advisories/34724
Url : http://secunia.com/advisories/35284
Url : http://secunia.com/advisories/35360
Url : http://secunia.com/advisories/35395
Url : http://secunia.com/advisories/35444
Url : http://secunia.com/advisories/35487
Url : http://secunia.com/advisories/35565
Url : http://secunia.com/advisories/35710
Url : http://secunia.com/advisories/35797
Url : http://secunia.com/advisories/35843
Url : http://secunia.com/advisories/36473
Url : http://secunia.com/advisories/37221

Source : SLACKWARE
Url : http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.538210

Source : SUSE
Url : http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html

Source : UBUNTU
Url : http://www.ubuntu.com/usn/usn-786-1
Url : http://www.ubuntu.com/usn/usn-787-1

Source : VUPEN
Url : http://www.vupen.com/english/advisories/2009/1907
Url : http://www.vupen.com/english/advisories/2009/3184
Url : http://www.vupen.com/english/advisories/2010/1107