CVE-2009-1956

CWE-18910 documents9 sources
Severity
6.4MEDIUM
EPSS
5.4%
top 9.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 8
Latest updateMay 2

Description

Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via crafted input.

CVSS vector

AV:N/AC:L/C:P/I:N/A:PExploitability: 10.0 | Impact: 4.9

Affected Packages3 packages

NVDapache/apr-util1.3.4
NVDapache/http_server2.2.02.2.12
Debianapr-util< 1.3.7+dfsg-1+3

Also affects: Ubuntu Linux 6.06, 8.04, 8.10, 9.04

Patches

🔴Vulnerability Details

3
GHSA
GHSA-4wj9-j34x-wjxp: Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 12022-05-02
OSV
CVE-2009-1956: Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 12009-06-08
CVEList
CVE-2009-1956: Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 12009-06-06

📋Vendor Advisories

5
Ubuntu
Apache vulnerabilities2009-06-11
Ubuntu
apr-util vulnerabilities2009-06-10
Red Hat
apr-util single NULL byte buffer overflow2009-04-24
Debian
CVE-2009-1956: apr-util - Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1...2009
Apache
Apache httpd: CVE-2009-1956

💬Community

1
Bugzilla
CVE-2009-1956 apr-util single NULL byte buffer overflow2009-06-06
CVE-2009-1956 (MEDIUM CVSS 6.4) | Off-by-one error in the apr_brigade | cvebase.io