CVE-2009-0023

Publication date 8 June 2009

Last updated 24 July 2024


Ubuntu priority

The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-util before 1.3.5 allows remote attackers to cause a denial of service (daemon crash) via crafted input involving (1) a .htaccess file used with the Apache HTTP Server, (2) the SVNMasterURI directive in the mod_dav_svn module in the Apache HTTP Server, (3) the mod_apreq2 module for the Apache HTTP Server, or (4) an application that uses the libapreq2 library, which triggers a heap-based buffer underflow.

Status

Package Ubuntu Release Status
apache2 9.04 jaunty
Not affected
8.10 intrepid
Not affected
8.04 LTS hardy
Not affected
6.06 LTS dapper
Fixed 2.0.55-4ubuntu2.5
apr-util 9.04 jaunty
Fixed 1.2.12+dfsg-8ubuntu0.1
8.10 intrepid
Fixed 1.2.12+dfsg-7ubuntu0.1
8.04 LTS hardy
Fixed 1.2.12+dfsg-3ubuntu0.1
6.06 LTS dapper Not in release

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
apr-util

References

Related Ubuntu Security Notices (USN)

    • USN-786-1
    • apr-util vulnerabilities
    • 10 June 2009
    • USN-787-1
    • Apache vulnerabilities
    • 11 June 2009

Other references