First published: Sat Jun 06 2009(Updated: )
Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via crafted input.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache APR-util | <=1.3.4 | |
Apache HTTP server | >=2.2.0<2.2.12 | |
Canonical Ubuntu Linux | =9.04 | |
Canonical Ubuntu Linux | =8.10 | |
Canonical Ubuntu Linux | =8.04 | |
Canonical Ubuntu Linux | =6.06 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.