CVE-2009-1956
published 2009-06-08CVE-2009-1956: Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive…
PriorityP429medium6.4CVSS 2.0
AVNACLAuNCPINAP
EPSS
12.04%
95.7th percentile
Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via crafted input.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | apr-util | <= 1.3.4 | — |
| apache | apr-util | >= 0 < 1.3.7+dfsg-1 | 1.3.7+dfsg-1 |
| apache | apr-util | >= 0 < 1.3.7+dfsg-1 | 1.3.7+dfsg-1 |
| apache | apr-util | >= 0 < 1.3.7+dfsg-1 | 1.3.7+dfsg-1 |
| apache | apr-util | >= 0 < 1.3.7+dfsg-1 | 1.3.7+dfsg-1 |
| apache | http_server | >= 2.2.0 < 2.2.12 | 2.2.12 |
| apache | httpd | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | apr-util | < apr-util 1.3.7+dfsg-1 (bookworm) | apr-util 1.3.7+dfsg-1 (bookworm) |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
osv6.4MEDIUM
vendor_apache6.4
vendor_debian6.4LOW
vendor_redhat6.4MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Apache vulnerabilities
vendor_ubuntu·2009-06-11·CVSS 4.3
CVE-2009-1195 [MEDIUM] Apache vulnerabilities
Title: Apache vulnerabilities
Summary: Apache vulnerabilities
Matthew Palmer discovered an underflow flaw in apr-util as included in
Apache. An attacker could cause a denial of service via application crash
in Apache using a crafted SVNMasterURI directive, .htaccess file, or when
using mod_apreq2. This issue only affected Ubuntu 6.06 LTS. (CVE-2009-0023)
Sander de Boer discovered that mod_proxy_ajp would reuse connections when
a client closed a connection without sending a request body. A remote
attacker could exploit this to obtain sensitive response data. This issue
only affected Ubuntu 9.04. (CVE-2009-1191)
Jonathan Peatfield discovered that Apache did not process Includes options
correctly. With certain configurations of Options and AllowOverride, a
local attacker could use an .hta
Ubuntu
apr-util vulnerabilities
vendor_ubuntu·2009-06-10·CVSS 4.3
CVE-2009-0023 [MEDIUM] apr-util vulnerabilities
Title: apr-util vulnerabilities
Summary: apr-util vulnerabilities
Matthew Palmer discovered an underflow flaw in apr-util. An attacker could
cause a denial of service via application crash in Apache using a crafted
SVNMasterURI directive, .htaccess file, or when using mod_apreq2.
Applications using libapreq2 are also affected. (CVE-2009-0023)
It was discovered that the XML parser did not properly handle entity
expansion. A remote attacker could cause a denial of service via memory
resource consumption by sending a crafted request to an Apache server
configured to use mod_dav or mod_dav_svn. (CVE-2009-1955)
C. Michael Pilato discovered an off-by-one buffer overflow in apr-util when
formatting certain strings. For big-endian machines (powerpc, hppa and
sparc in Ubuntu), a remote attacker
Red Hat
apr-util single NULL byte buffer overflow
vendor_redhat·2009-04-24·CVSS 6.4
CVE-2009-1956 [MEDIUM] apr-util single NULL byte buffer overflow
apr-util single NULL byte buffer overflow
Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via crafted input.
Debian
CVE-2009-1956: apr-util - Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1...
vendor_debian·2009·CVSS 6.4
CVE-2009-1956 [MEDIUM] CVE-2009-1956: apr-util - Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1...
Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via crafted input.
Scope: local
bookworm: resolved (fixed in 1.3.7+dfsg-1)
bullseye: resolved (fixed in 1.3.7+dfsg-1)
forky: resolved (fixed in 1.3.7+dfsg-1)
sid: resolved (fixed in 1.3.7+dfsg-1)
trixie: resolved (fixed in 1.3.7+dfsg-1)
Apache
Apache httpd: CVE-2009-1956
vendor_apache·CVSS 6.4
CVE-2009-1956 Apache httpd: CVE-2009-1956
Apache httpd: CVE-2009-1956
An off-by-one overflow flaw was found in the way the bundled copy of the APR-util library processed a variable list of arguments. An attacker could provide a specially-crafted string as input for the formatted output conversion routine, which could, on big-endian platforms, potentially lead to the disclosure of sensitive information or a denial of service. Reported to security team 2009-04-24 Issue public 2009-04-24 Update 2.2.12 released 2009-07-27 Affects 2.2.11, 2.2.10, 2.2.9, 2.2.8, 2.2.6, 2.2.5, 2.2.4, 2.2.3, 2.2.2, 2.2.0
Severity: moderate
GHSA
GHSA-4wj9-j34x-wjxp: Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1
ghsa_unreviewed·2022-05-02
CVE-2009-1956 [MEDIUM] GHSA-4wj9-j34x-wjxp: Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1
Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via crafted input.
OSV
CVE-2009-1956: Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1
osv·2009-06-08·CVSS 6.4
CVE-2009-1956 [MEDIUM] CVE-2009-1956: Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1
Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via crafted input.
No detection rules found.
No public exploits indexed.
http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.htmlhttp://marc.info/?l=bugtraq&m=129190899612998&w=2http://secunia.com/advisories/34724http://secunia.com/advisories/35284http://secunia.com/advisories/35395http://secunia.com/advisories/35487http://secunia.com/advisories/35565http://secunia.com/advisories/35710http://secunia.com/advisories/35797http://secunia.com/advisories/35843http://secunia.com/advisories/37221http://security.gentoo.org/glsa/glsa-200907-03.xmlhttp://support.apple.com/kb/HT3937http://svn.apache.org/viewvc?view=rev&revision=768417http://www-01.ibm.com/support/docview.wss?uid=swg1PK88341http://www-01.ibm.com/support/docview.wss?uid=swg1PK91241http://www-01.ibm.com/support/docview.wss?uid=swg1PK99478http://www-01.ibm.com/support/docview.wss?uid=swg27014463http://www.apache.org/dist/apr/CHANGES-APR-UTIL-1.3http://www.mail-archive.com/dev%40apr.apache.org/msg21591.htmlhttp://www.mail-archive.com/dev%40apr.apache.org/msg21592.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2009:131http://www.mandriva.com/security/advisories?name=MDVSA-2013:150http://www.openwall.com/lists/oss-security/2009/06/06/1http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1107.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1108.htmlhttp://www.securityfocus.com/bid/35251http://www.ubuntu.com/usn/usn-786-1http://www.ubuntu.com/usn/usn-787-1http://www.vupen.com/english/advisories/2009/1907http://www.vupen.com/english/advisories/2009/3184https://bugzilla.redhat.com/show_bug.cgi?id=504390https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r2295080a257bad27ea68ca0af12fc715577f9e84801eae116a33107e%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rad2acee3ab838b52c04a0698b1728a9a43467bf365bd481c993c535d%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/reb7c64aeea604bf948467d9d1cab8ff23fa7d002be1964bcc275aae7%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3Ehttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11567https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12237https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01173.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-June/msg01201.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-June/msg01228.htmlhttp://lists.apple.com/archives/security-announce/2009/Nov/msg00000.htmlhttp://marc.info/?l=bugtraq&m=129190899612998&w=2http://secunia.com/advisories/34724http://secunia.com/advisories/35284http://secunia.com/advisories/35395http://secunia.com/advisories/35487http://secunia.com/advisories/35565http://secunia.com/advisories/35710http://secunia.com/advisories/35797http://secunia.com/advisories/35843http://secunia.com/advisories/37221http://security.gentoo.org/glsa/glsa-200907-03.xmlhttp://support.apple.com/kb/HT3937http://svn.apache.org/viewvc?view=rev&revision=768417http://www-01.ibm.com/support/docview.wss?uid=swg1PK88341http://www-01.ibm.com/support/docview.wss?uid=swg1PK91241http://www-01.ibm.com/support/docview.wss?uid=swg1PK99478http://www-01.ibm.com/support/docview.wss?uid=swg27014463http://www.apache.org/dist/apr/CHANGES-APR-UTIL-1.3http://www.mail-archive.com/dev%40apr.apache.org/msg21591.htmlhttp://www.mail-archive.com/dev%40apr.apache.org/msg21592.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2009:131http://www.mandriva.com/security/advisories?name=MDVSA-2013:150http://www.openwall.com/lists/oss-security/2009/06/06/1http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1107.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1108.htmlhttp://www.securityfocus.com/bid/35251http://www.ubuntu.com/usn/usn-786-1http://www.ubuntu.com/usn/usn-787-1http://www.vupen.com/english/advisories/2009/1907http://www.vupen.com/english/advisories/2009/3184https://bugzilla.redhat.com/show_bug.cgi?id=504390https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r2295080a257bad27ea68ca0af12fc715577f9e84801eae116a33107e%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rad2acee3ab838b52c04a0698b1728a9a43467bf365bd481c993c535d%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/reb7c64aeea604bf948467d9d1cab8ff23fa7d002be1964bcc275aae7%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3Ehttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11567https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12237https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01173.html
+ 2 more references
2009-06-08
Published