CVE-2009-0023
published 2009-06-08CVE-2009-0023: The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-util before 1.3.5 allows remote attackers to cause a denial of service (daemon…
PriorityP424medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
8.53%
94.4th percentile
The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-util before 1.3.5 allows remote attackers to cause a denial of service (daemon crash) via crafted input involving (1) a .htaccess file used with the Apache HTTP Server, (2) the SVNMasterURI directive in the mod_dav_svn module in the Apache HTTP Server, (3) the mod_apreq2 module for the Apache HTTP Server, or (4) an application that uses the libapreq2 library, which triggers a heap-based buffer underflow.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | apr-util | <= 1.3.4 | — |
| apache | apr-util | — | — |
| apache | apr-util | — | — |
| apache | apr-util | — | — |
| apache | apr-util | — | — |
| apache | apr-util | — | — |
| apache | apr-util | — | — |
| apache | apr-util | — | — |
| apache | apr-util | — | — |
| apache | apr-util | — | — |
| apache | apr-util | — | — |
| apache | apr-util | — | — |
| apache | apr-util | — | — |
| apache | apr-util | — | — |
| apache | apr-util | — | — |
| apache | apr-util | — | — |
| apache | apr-util | — | — |
| apache | apr-util | — | — |
| apache | apr-util | — | — |
| apache | apr-util | — | — |
| apache | apr-util | — | — |
| apache | apr-util | >= 0 < 1.3.7+dfsg-1 | 1.3.7+dfsg-1 |
| apache | apr-util | >= 0 < 1.3.7+dfsg-1 | 1.3.7+dfsg-1 |
| apache | apr-util | >= 0 < 1.3.7+dfsg-1 | 1.3.7+dfsg-1 |
| apache | apr-util | >= 0 < 1.3.7+dfsg-1 | 1.3.7+dfsg-1 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Apache vulnerabilities
vendor_ubuntu·2009-06-11·CVSS 4.3
CVE-2009-1195 [MEDIUM] Apache vulnerabilities
Title: Apache vulnerabilities
Summary: Apache vulnerabilities
Matthew Palmer discovered an underflow flaw in apr-util as included in
Apache. An attacker could cause a denial of service via application crash
in Apache using a crafted SVNMasterURI directive, .htaccess file, or when
using mod_apreq2. This issue only affected Ubuntu 6.06 LTS. (CVE-2009-0023)
Sander de Boer discovered that mod_proxy_ajp would reuse connections when
a client closed a connection without sending a request body. A remote
attacker could exploit this to obtain sensitive response data. This issue
only affected Ubuntu 9.04. (CVE-2009-1191)
Jonathan Peatfield discovered that Apache did not process Includes options
correctly. With certain configurations of Options and AllowOverride, a
local attacker could use an .hta
Ubuntu
apr-util vulnerabilities
vendor_ubuntu·2009-06-10·CVSS 4.3
CVE-2009-0023 [MEDIUM] apr-util vulnerabilities
Title: apr-util vulnerabilities
Summary: apr-util vulnerabilities
Matthew Palmer discovered an underflow flaw in apr-util. An attacker could
cause a denial of service via application crash in Apache using a crafted
SVNMasterURI directive, .htaccess file, or when using mod_apreq2.
Applications using libapreq2 are also affected. (CVE-2009-0023)
It was discovered that the XML parser did not properly handle entity
expansion. A remote attacker could cause a denial of service via memory
resource consumption by sending a crafted request to an Apache server
configured to use mod_dav or mod_dav_svn. (CVE-2009-1955)
C. Michael Pilato discovered an off-by-one buffer overflow in apr-util when
formatting certain strings. For big-endian machines (powerpc, hppa and
sparc in Ubuntu), a remote attacker
Red Hat
apr-util heap buffer underwrite
vendor_redhat·2009-06-03·CVSS 4.3
CVE-2009-0023 [MEDIUM] apr-util heap buffer underwrite
apr-util heap buffer underwrite
The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-util before 1.3.5 allows remote attackers to cause a denial of service (daemon crash) via crafted input involving (1) a .htaccess file used with the Apache HTTP Server, (2) the SVNMasterURI directive in the mod_dav_svn module in the Apache HTTP Server, (3) the mod_apreq2 module for the Apache HTTP Server, or (4) an application that uses the libapreq2 library, which triggers a heap-based buffer underflow.
Debian
CVE-2009-0023: apr-util - The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-ut...
vendor_debian·2009·CVSS 4.3
CVE-2009-0023 [MEDIUM] CVE-2009-0023: apr-util - The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-ut...
The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-util before 1.3.5 allows remote attackers to cause a denial of service (daemon crash) via crafted input involving (1) a .htaccess file used with the Apache HTTP Server, (2) the SVNMasterURI directive in the mod_dav_svn module in the Apache HTTP Server, (3) the mod_apreq2 module for the Apache HTTP Server, or (4) an application that uses the libapreq2 library, which triggers a heap-based buffer underflow.
Scope: local
bookworm: resolved (fixed in 1.3.7+dfsg-1)
bullseye: resolved (fixed in 1.3.7+dfsg-1)
forky: resolved (fixed in 1.3.7+dfsg-1)
sid: resolved (fixed in 1.3.7+dfsg-1)
trixie: resolved (fixed in 1.3.7+dfsg-1)
GHSA
GHSA-8jp8-5574-2q6q: The apr_strmatch_precompile function in strmatch/apr_strmatch
ghsa_unreviewed·2022-05-02
CVE-2009-0023 [MEDIUM] CWE-119 GHSA-8jp8-5574-2q6q: The apr_strmatch_precompile function in strmatch/apr_strmatch
The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-util before 1.3.5 allows remote attackers to cause a denial of service (daemon crash) via crafted input involving (1) a .htaccess file used with the Apache HTTP Server, (2) the SVNMasterURI directive in the mod_dav_svn module in the Apache HTTP Server, (3) the mod_apreq2 module for the Apache HTTP Server, or (4) an application that uses the libapreq2 library, which triggers a heap-based buffer underflow.
OSV
CVE-2009-0023: The apr_strmatch_precompile function in strmatch/apr_strmatch
osv·2009-06-08·CVSS 4.3
CVE-2009-0023 [MEDIUM] CVE-2009-0023: The apr_strmatch_precompile function in strmatch/apr_strmatch
The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-util before 1.3.5 allows remote attackers to cause a denial of service (daemon crash) via crafted input involving (1) a .htaccess file used with the Apache HTTP Server, (2) the SVNMasterURI directive in the mod_dav_svn module in the Apache HTTP Server, (3) the mod_apreq2 module for the Apache HTTP Server, or (4) an application that uses the libapreq2 library, which triggers a heap-based buffer underflow.
No detection rules found.
Exploit-DB
WarFTPd 1.82.00-RC12 - 'LIST' Format String Denial of Service
exploitdb·2009-09-10
CVE-2009-5141 WarFTPd 1.82.00-RC12 - 'LIST' Format String Denial of Service
WarFTPd 1.82.00-RC12 - 'LIST' Format String Denial of Service
---
# [*] Vulnerability : War FTP Daemon Format String DoS (LIST command)
# [*] Detected by : corelanc0d3r (corelanc0d3r[at]gmail[dot]com)
# [*] Type : remote DoS
# [*] OS : Windows
# [*] Product : Jgaa's War FTP Daemon
# [*] Versions affected : 1.82 RC 12
# [*] Download link : http://www.warftp.org/?menu=344
# [*] -------------------------------------------------------------------------
# [*] Method : format string, only works with anonymous access
# [*] Crash information
#(8cc.598): Access violation - code c0000005 (!!! second chance !!!)
#eax=00000001 ebx=0076e7b0 ecx=00000073 edx=00000002 esi=0076e6fe edi=0000000a
#eip=00431680 esp=0076e6c0 ebp=00a1114a iopl=0 nv up ei pl nz na po nc
#cs=001b ss=0023 ds=0023 es=0023 fs=003
Exploit-DB
Music Tag Editor 1.61 build 212 - Remote Buffer Overflow (PoC)
exploitdb·2009-07-16
CVE-2009-3811 Music Tag Editor 1.61 build 212 - Remote Buffer Overflow (PoC)
Music Tag Editor 1.61 build 212 - Remote Buffer Overflow (PoC)
---
==
* Music Tag Editor 1.61 build 212 Remote Buffer Overflow PoC *
Product: http://www.assistanttools.com/products/tag_editors/music_tag_editor/index.shtml
Tested On Microsoft Windows XP Professional SP3 (English)
Vulnerability Discovered By Gjoko 'LiquidWorm' Krstic
liquidworm gmail com
Zero Science Lab - http://www.zeroscience.org/
15.07.2009
==
(8bc.86c): Access violation - code c0000005 (first chance)
First chance exceptions are reported before any exception handling.
This exception may be expected and handled.
eax=00410041 ebx=00000000 ecx=0010fa80 edx=00410041 esi=001e5fb0 edi=000fd060
eip=cccccccc esp=000fcfa0 ebp=000fcff8 iopl=0 nv up ei pl nz ac po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=000102
Exploit-DB
ICQ 6.5 - URL Search Hook (Windows Explorer) Remote Buffer Overflow (PoC)
exploitdb·2009-06-01
CVE-2009-1915 ICQ 6.5 - URL Search Hook (Windows Explorer) Remote Buffer Overflow (PoC)
ICQ 6.5 - URL Search Hook (Windows Explorer) Remote Buffer Overflow (PoC)
---
g
(f44.104): Access violation - code c0000005 (!!! second chance !!!)
eax=02100068 ebx=772a23c1 ecx=0210cefa edx=00000823 esi=00610061 edi=00000000
eip=772a533f esp=0210cec0 ebp=0210cec4 iopl=0 nv up ei pl nz na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00010202
SHLWAPI!Ordinal400+0x2d:
772a533f 668906 mov word ptr [esi],ax ds:0023:00610061=???? gn
eax=00000001 ebx=00000000 ecx=00000000 edx=00000000 esi=00000000 edi=00000001
eip=7ffe0304 esp=0178fcf0 ebp=0178ff44 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
SharedUserData!SystemCallStub+0x4:
7ffe0304 c3 ret
prepare a network folder with the .url file inside. This works
against Internet Explorer too
Exploit-DB
32bit FTP (09.04.24) - 'Banner' Remote Buffer Overflow (PoC)
exploitdb·2009-05-05
CVE-2009-1592 32bit FTP (09.04.24) - 'Banner' Remote Buffer Overflow (PoC)
32bit FTP (09.04.24) - 'Banner' Remote Buffer Overflow (PoC)
---
#!/usr/bin/perl
#
# A client side vulnerability in the product allows remote servers to cause the client to crash by sending it a large banner.
# By: Load 99%
#
# website: http://www.electrasoft.com/32ftp.htm
# Version:09.04.24
#
#0:005> g
# ...
#(9b0.bac): Access violation - code c0000005 (first chance)
#First chance exceptions are reported before any exception handling.
#This exception may be expected and handled.
#eax=41414141 ebx=00000001 ecx=000013e7 edx=0382ec14 esi=fffffffe edi=00000000
#eip=41414141 esp=0382f018 ebp=0382f050 iopl=0 nv up ei pl nz na pe nc
#cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00010206
#41414141 ?? ???
#
use IO::Socket::INET;
my $socket = IO::Socket::INET->new('LocalPort' => 21,
'Prot
Exploit-DB
Elecard MPEG Player 5.5 - '.m3u' Stack Buffer Overflow (PoC)
exploitdb·2009-01-01
CVE-2009-0491 Elecard MPEG Player 5.5 - '.m3u' Stack Buffer Overflow (PoC)
Elecard MPEG Player 5.5 - '.m3u' Stack Buffer Overflow (PoC)
---
#!/usr/bin/perl -w
########################################################################
#Program : Elecard MPEG Player
#Version : 5.5 build 15884.081218
#website : http://www.elecard.com/download/index.php
#Download : http://www.elecard.com/ftp/pub/mpeg/player/EMpgPlayer.zip
#Type : * (.M3U) Buffer Overflow POC
########################################################################
#EAX 00000000
#ECX 41414141
#EDX 7C9037D8 ntdll.7C9037D8
#EBX 00000000
#ESP 0012BE40
#EBP 0012BE60
#ESI 00000000
#EDI 00000000
#EIP 41414141
#C 0 ES 0023 32bit 0(FFFFFFFF)
#P 1 CS 001B 32bit 0(FFFFFFFF)
#A 0 SS 0023 32bit 0(FFFFFFFF)
#Z 1 DS 0023 32bit 0(FFFFFFFF)
#S 0 FS 003B 32bit 7FFDF000(FFF)
#T 0 GS 0000 NULL
#D 0
#O 0
#EFL 00210246 (
Bugzilla
Moodle: Multiple security fixes in 1.9.7 and 1.8.11 upstream releases
bugzilla·2009-12-06·CVSS 6.8
CVE-2009-4297 [MEDIUM] Moodle: Multiple security fixes in 1.9.7 and 1.8.11 upstream releases
Moodle: Multiple security fixes in 1.9.7 and 1.8.11 upstream releases
Moodle upstream has released latest stable versions (1.9.7 and 1.8.11),
fixing multiple security issues.
The list for 1.9.7 release:
Security issues
* MSA-09-0022 - CVE-2009-4297 Multiple CSRF problems fixed
* MSA-09-0023 - CVE-2009-4298 Fixed user account disclosure in LAMS module
* MSA-09-0024 - CVE-2009-4299 Fixed insufficient access control in
Glossary module
* MSA-09-0025 - CVE-2009-4300 Unneeded MD5 hashes removed from user table
* MSA-09-0026 - CVE-2009-4301 Fixed invalid application access control
in MNET interface
* MSA-09-0027 - CVE-2009-4302 Ensured login information is always sent
secured when using SSL for logins
* MSA-09-0028 - CVE-2009-4303 Passwords and secrets are no longer ever
saved in backups, new
Bugzilla
CVE-2009-0023 apr-util heap buffer underwrite
bugzilla·2009-06-03·CVSS 4.3
CVE-2009-0023 [MEDIUM] CVE-2009-0023 apr-util heap buffer underwrite
CVE-2009-0023 apr-util heap buffer underwrite
A heap buffer underwrite flaw was found in apr-util's apr_strmatch_precompile() function.
This flaw could allow a remote attacker to overwrite arbitrary heap memory.
The upstream fix is here:
http://svn.apache.org/viewvc?view=rev&revision=779880
Discussion:
After looking through the things in RHEL that use this fuction, nothing is using it to parse untrusted remote data. Everything uses this function to parse configuration data, which significantly reduces the severity of this flaw.
---
This subsequent change:
http://svn.apache.org/viewvc?view=rev&revision=781063
fixes another instance of the same mistake, but in this case it would seem to result in only a buffer underread, not a write. I'll include both changes.
---
This issue has b
http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.htmlhttp://marc.info/?l=bugtraq&m=129190899612998&w=2http://secunia.com/advisories/34724http://secunia.com/advisories/35284http://secunia.com/advisories/35360http://secunia.com/advisories/35395http://secunia.com/advisories/35444http://secunia.com/advisories/35487http://secunia.com/advisories/35565http://secunia.com/advisories/35710http://secunia.com/advisories/35797http://secunia.com/advisories/35843http://secunia.com/advisories/37221http://security.gentoo.org/glsa/glsa-200907-03.xmlhttp://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.538210http://support.apple.com/kb/HT3937http://svn.apache.org/viewvc?view=rev&revision=779880http://wiki.rpath.com/Advisories:rPSA-2009-0144http://www-01.ibm.com/support/docview.wss?uid=swg1PK88341http://www-01.ibm.com/support/docview.wss?uid=swg1PK91241http://www-01.ibm.com/support/docview.wss?uid=swg1PK99478http://www-01.ibm.com/support/docview.wss?uid=swg27014463http://www.apache.org/dist/apr/CHANGES-APR-UTIL-1.3http://www.debian.org/security/2009/dsa-1812http://www.mandriva.com/security/advisories?name=MDVSA-2009:131http://www.mandriva.com/security/advisories?name=MDVSA-2013:150http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1107.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1108.htmlhttp://www.securityfocus.com/archive/1/507855/100/0/threadedhttp://www.securityfocus.com/bid/35221http://www.ubuntu.com/usn/usn-786-1http://www.ubuntu.com/usn/usn-787-1http://www.vupen.com/english/advisories/2009/1907http://www.vupen.com/english/advisories/2009/3184https://bugzilla.redhat.com/show_bug.cgi?id=503928https://exchange.xforce.ibmcloud.com/vulnerabilities/50964https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r8c9983f1172a3415f915ddb7e14de632d2d0c326eb1285755a024165%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3Ehttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10968https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12321https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01173.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-June/msg01201.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-June/msg01228.htmlhttp://lists.apple.com/archives/security-announce/2009/Nov/msg00000.htmlhttp://marc.info/?l=bugtraq&m=129190899612998&w=2http://secunia.com/advisories/34724http://secunia.com/advisories/35284http://secunia.com/advisories/35360http://secunia.com/advisories/35395http://secunia.com/advisories/35444http://secunia.com/advisories/35487http://secunia.com/advisories/35565http://secunia.com/advisories/35710http://secunia.com/advisories/35797http://secunia.com/advisories/35843http://secunia.com/advisories/37221http://security.gentoo.org/glsa/glsa-200907-03.xmlhttp://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.538210http://support.apple.com/kb/HT3937http://svn.apache.org/viewvc?view=rev&revision=779880http://wiki.rpath.com/Advisories:rPSA-2009-0144http://www-01.ibm.com/support/docview.wss?uid=swg1PK88341http://www-01.ibm.com/support/docview.wss?uid=swg1PK91241http://www-01.ibm.com/support/docview.wss?uid=swg1PK99478http://www-01.ibm.com/support/docview.wss?uid=swg27014463http://www.apache.org/dist/apr/CHANGES-APR-UTIL-1.3http://www.debian.org/security/2009/dsa-1812http://www.mandriva.com/security/advisories?name=MDVSA-2009:131http://www.mandriva.com/security/advisories?name=MDVSA-2013:150http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1107.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1108.htmlhttp://www.securityfocus.com/archive/1/507855/100/0/threadedhttp://www.securityfocus.com/bid/35221http://www.ubuntu.com/usn/usn-786-1http://www.ubuntu.com/usn/usn-787-1http://www.vupen.com/english/advisories/2009/1907http://www.vupen.com/english/advisories/2009/3184https://bugzilla.redhat.com/show_bug.cgi?id=503928https://exchange.xforce.ibmcloud.com/vulnerabilities/50964https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r8c9983f1172a3415f915ddb7e14de632d2d0c326eb1285755a024165%40%3Ccvs.httpd.apache.org%3E
+ 12 more references
2009-06-08
Published