This Alert is flagged as TOP 25 Common Weakness Enumeration from CWE/SANS. For more information, you can read this.

INFORMATION

Name : CVE-2009-1956 First Publication : 2009-06-07
Severity : Medium Last Modification : 2010-08-21

SCORING CVSS v2

Cvss Base Score : 6.4 Attack Range : Network
Cvss Impact Score : 4.9 Attack Complexity : Low
Cvss Expoit Score : 10 Authentification : None Required

Calculate full CVSS 2.0 Vectors scores

DETAIL

Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via crafted input.



CWE COMMON WEAKNESS ENUMERATION

CWE-189 - Numeric Errors (CWE/SANS Top 25)

OVALID

oval:org.mitre.oval:def:11567, Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via crafted input.

oval:org.mitre.oval:def:11782, The operating system installed on the system is Red Hat Enterprise Linux 3
oval:org.mitre.oval:def:11831, The operating system installed on the system is Red Hat Enterprise Linux 4
oval:org.mitre.oval:def:11414, The operating system installed on the system is Red Hat Enterprise Linux 5

CPE COMMON PLATFORM ENUMERATION

OPEN SOURCE VULNERABILTY DATABASE (OSVDB)

55058 : Apache APR-util apr_brigade_vprintf Function Crafted Input Off-by-one Remote DoS.


SECONDARY(S) SOURCE(S)


Source : AIXAPAR
Url : http://www-01.ibm.com/support/docview.wss?uid=swg1PK88341
Url : http://www-01.ibm.com/support/docview.wss?uid=swg1PK91241
Url : http://www-01.ibm.com/support/docview.wss?uid=swg1PK99478

Source : APPLE
Url : http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html

Source : BID
Url : http://www.securityfocus.com/bid/35251

Source : CONFIRM
Url : http://support.apple.com/kb/HT3937
Url : http://svn.apache.org/viewvc?view=rev&revision=768417
Url : http://www-01.ibm.com/support/docview.wss?uid=swg27014463
Url : http://www.apache.org/dist/apr/CHANGES-APR-UTIL-1.3
Url : https://bugzilla.redhat.com/show_bug.cgi?id=504390

Source : FEDORA
Url : https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01173.html
Url : https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01201.html
Url : https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01228.html

Source : GENTOO
Url : http://security.gentoo.org/glsa/glsa-200907-03.xml

Source : MANDRIVA
Url : http://www.mandriva.com/security/advisories?name=MDVSA-2009:131

Source : MLIST
Url : http://www.mail-archive.com/dev@apr.apache.org/msg21591.html
Url : http://www.mail-archive.com/dev@apr.apache.org/msg21592.html
Url : http://www.openwall.com/lists/oss-security/2009/06/06/1

Source : REDHAT
Url : http://www.redhat.com/support/errata/RHSA-2009-1107.html
Url : http://www.redhat.com/support/errata/RHSA-2009-1108.html

Source : SECUNIA
Url : http://secunia.com/advisories/34724
Url : http://secunia.com/advisories/35284
Url : http://secunia.com/advisories/35395
Url : http://secunia.com/advisories/35487
Url : http://secunia.com/advisories/35565
Url : http://secunia.com/advisories/35710
Url : http://secunia.com/advisories/35797
Url : http://secunia.com/advisories/35843
Url : http://secunia.com/advisories/37221

Source : UBUNTU
Url : http://www.ubuntu.com/usn/usn-786-1
Url : http://www.ubuntu.com/usn/usn-787-1

Source : VUPEN
Url : http://www.vupen.com/english/advisories/2009/1907
Url : http://www.vupen.com/english/advisories/2009/3184