CVE-2009-1956
Severity
6.4MEDIUM
EPSS
5.4%
top 9.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 8
Latest updateMay 2
Description
Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via crafted input.
CVSS vector
AV:N/AC:L/C:P/I:N/A:PExploitability: 10.0 | Impact: 4.9
Affected Packages3 packages
Also affects: Ubuntu Linux 6.06, 8.04, 8.10, 9.04
Patches
🔴Vulnerability Details
3GHSA▶
GHSA-4wj9-j34x-wjxp: Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1↗2022-05-02
OSV▶
CVE-2009-1956: Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1↗2009-06-08
CVEList▶
CVE-2009-1956: Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1↗2009-06-06