CVE-2009-0023
Last modified
CVE-2009-0023 is a vulnerability of currently unknown severity. The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-util before 1.3.5 allows remote attackers to cause a denial of service (daemon crash) via crafted input involving (1) a .htaccess file used with the Apache HTTP Server, (2) the SVNMasterURI directive in the mod_dav_svn module in the Apache HTTP Server, (3) the mod_apreq2 module for the Apache HTTP Server, or (4) an application that uses the libapreq2 library, which triggers a heap-based buffer underflow.. EPSS estimates a 8.53% chance of exploitation in the next 30 days.
Description
The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-util before 1.3.5 allows remote attackers to cause a denial of service (daemon crash) via crafted input involving (1) a .htaccess file used with the Apache HTTP Server, (2) the SVNMasterURI directive in the mod_dav_svn module in the Apache HTTP Server, (3) the mod_apreq2 module for the Apache HTTP Server, or (4) an application that uses the libapreq2 library, which triggers a heap-based buffer underflow.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Apr-Util | <= 1.3.4 |
| Apache | Apr-Util | 0.9.1 |
| Apache | Apr-Util | 0.9.2 |
| Apache | Apr-Util | 0.9.3 |
| Apache | Apr-Util | 0.9.4 |
| Apache | Apr-Util | 0.9.5 |
| Apache | Apr-Util | 1.0 |
| Apache | Apr-Util | 1.0.1 |
| Apache | Apr-Util | 1.0.2 |
| Apache | Apr-Util | 1.1.0 |
| Apache | Apr-Util | 1.1.1 |
| Apache | Apr-Util | 1.1.2 |
| Apache | Apr-Util | 1.2.1 |
| Apache | Apr-Util | 1.2.2 |
| Apache | Apr-Util | 1.2.6 |
| Apache | Apr-Util | 1.2.7 |
| Apache | Apr-Util | 1.2.8 |
| Apache | Apr-Util | 1.3.0 |
| Apache | Apr-Util | 1.3.1 |
| Apache | Apr-Util | 1.3.2 |
| Apache | Apr-Util | 1.3.3 |
| Apache | Http Server | >= 2.2.0, < 2.2.12 |
References
- http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.htmlMailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=129190899612998&w=2Third Party Advisory
- http://secunia.com/advisories/34724Third Party Advisory
- http://secunia.com/advisories/35284Third Party Advisory, Vendor Advisory
- http://secunia.com/advisories/35360Third Party Advisory, Vendor Advisory
- http://secunia.com/advisories/35395Third Party Advisory
- http://secunia.com/advisories/35444Third Party Advisory
- http://secunia.com/advisories/35487Third Party Advisory
- http://secunia.com/advisories/35565Third Party Advisory
- http://secunia.com/advisories/35710Third Party Advisory
- http://secunia.com/advisories/35797Third Party Advisory
- http://secunia.com/advisories/35843Third Party Advisory
- http://secunia.com/advisories/37221Third Party Advisory
- http://security.gentoo.org/glsa/glsa-200907-03.xmlThird Party Advisory
- http://support.apple.com/kb/HT3937Third Party Advisory
- http://svn.apache.org/viewvc?view=rev&revision=779880Third Party Advisory
- http://wiki.rpath.com/Advisories:rPSA-2009-0144Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1PK88341Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1PK91241Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1PK99478Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg27014463Third Party Advisory
- http://www.apache.org/dist/apr/CHANGES-APR-UTIL-1.3Third Party Advisory
- http://www.debian.org/security/2009/dsa-1812Patch, Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:131Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:150Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2009-1107.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2009-1108.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/507855/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/35221Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/usn-786-1Third Party Advisory
- http://www.ubuntu.com/usn/usn-787-1Third Party Advisory
- http://www.vupen.com/english/advisories/2009/1907Third Party Advisory
- http://www.vupen.com/english/advisories/2009/3184Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=503928Issue Tracking, Patch, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50964Third Party Advisory, VDB Entry
- https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01173.htmlThird Party Advisory
- https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01201.htmlThird Party Advisory
- https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01228.htmlThird Party Advisory
- http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.htmlMailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=129190899612998&w=2Third Party Advisory
- http://secunia.com/advisories/34724Third Party Advisory
- http://secunia.com/advisories/35284Third Party Advisory, Vendor Advisory
- http://secunia.com/advisories/35360Third Party Advisory, Vendor Advisory
- http://secunia.com/advisories/35395Third Party Advisory
- http://secunia.com/advisories/35444Third Party Advisory
- http://secunia.com/advisories/35487Third Party Advisory
- http://secunia.com/advisories/35565Third Party Advisory
- http://secunia.com/advisories/35710Third Party Advisory
- http://secunia.com/advisories/35797Third Party Advisory
- http://secunia.com/advisories/35843Third Party Advisory
- http://secunia.com/advisories/37221Third Party Advisory
- http://security.gentoo.org/glsa/glsa-200907-03.xmlThird Party Advisory
- http://support.apple.com/kb/HT3937Third Party Advisory
- http://svn.apache.org/viewvc?view=rev&revision=779880Third Party Advisory
- http://wiki.rpath.com/Advisories:rPSA-2009-0144Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1PK88341Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1PK91241Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1PK99478Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg27014463Third Party Advisory
- http://www.apache.org/dist/apr/CHANGES-APR-UTIL-1.3Third Party Advisory
- http://www.debian.org/security/2009/dsa-1812Patch, Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:131Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:150Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2009-1107.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2009-1108.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/507855/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/35221Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/usn-786-1Third Party Advisory
- http://www.ubuntu.com/usn/usn-787-1Third Party Advisory
- http://www.vupen.com/english/advisories/2009/1907Third Party Advisory
- http://www.vupen.com/english/advisories/2009/3184Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=503928Issue Tracking, Patch, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50964Third Party Advisory, VDB Entry
- https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01173.htmlThird Party Advisory
- https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01201.htmlThird Party Advisory
- https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01228.htmlThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-0023?
How severe is CVE-2009-0023?
How do I fix CVE-2009-0023?
Are you affected by CVE-2009-0023?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
