CVE-2009-1955: High severity Apache apr-util vulnerability
The expat XML parser in the aprxml interface in xml/aprxml.c in Apache APR-util before 1.3.7, as used in the moddav and moddavsvn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, as demonstrated by a PROPFIND request, a similar issue to CVE-2003-1564.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/httpd22to a version that resolves this vulnerability.Fixed in 0:2.2.10-23.1.ep5.el4 - Upgrade
Upgrade
redhat/pcsc-liteto a version that resolves this vulnerability.Fixed in 0:1.3.3-3.el4 - Upgrade
Upgrade
redhat/rhpki-cato a version that resolves this vulnerability.Fixed in 0:7.3.0-20.el4 - Upgrade
Upgrade
redhat/rhpki-java-toolsto a version that resolves this vulnerability.Fixed in 0:7.3.0-10.el4 - Upgrade
Upgrade
redhat/rhpki-krato a version that resolves this vulnerability.Fixed in 0:7.3.0-14.el4 - Upgrade
Upgrade
redhat/rhpki-manageto a version that resolves this vulnerability.Fixed in 0:7.3.0-19.el4 - Upgrade
Upgrade
redhat/rhpki-native-toolsto a version that resolves this vulnerability.Fixed in 0:7.3.0-6.el4 - Upgrade
Upgrade
redhat/rhpki-ocspto a version that resolves this vulnerability.Fixed in 0:7.3.0-13.el4 - Upgrade
Upgrade
redhat/rhpki-tksto a version that resolves this vulnerability.Fixed in 0:7.3.0-13.el4 - Upgrade
Upgrade
redhat/apr-utilto a version that resolves this vulnerability.Fixed in 0:0.9.4-22.el4_8.1 - Upgrade
Upgrade
redhat/apr-utilto a version that resolves this vulnerability.Fixed in 0:1.2.7-7.el5_3.1
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2009-1955?
CVE-2009-1955 has been classified as a moderate severity vulnerability due to its potential for causing denial of service by excessive memory consumption.
How do I fix CVE-2009-1955?
To fix CVE-2009-1955, update the affected Apache APR-util package to version 1.3.7 or later.
Which versions of Apache are affected by CVE-2009-1955?
CVE-2009-1955 affects Apache HTTP Server versions prior to 2.2.12 when using the vulnerable expat XML parser.
Can CVE-2009-1955 be exploited remotely?
Yes, CVE-2009-1955 can be exploited remotely by sending a specially crafted XML document to the affected server.
What components are affected by CVE-2009-1955 in Apache?
CVE-2009-1955 affects the expat XML parser utilized in the mod_dav and mod_dav_svn modules of Apache HTTP Server.