Hide Forgot
Common Vulnerabilities and Exposures assigned an identifier CVE-2009-1955 to the following vulnerability: The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, as demonstrated by a PROPFIND request, a similar issue to CVE-2003-1564.
*** Bug 503814 has been marked as a duplicate of this bug. ***
Public exploit posted to milw0rm: http://www.milw0rm.com/exploits/8842 Upstream patch: http://svn.apache.org/viewvc?view=rev&revision=781403 http://marc.info/?l=apr-dev&m=124396021826125&w=2
Note that the patch committed is different from the one posted to the list.
This issue has been addressed in following products: Red Hat Enterprise Linux 3 Via RHSA-2009:1108 https://rhn.redhat.com/errata/RHSA-2009-1108.html
This issue has been addressed in following products: Red Hat Enterprise Linux 5 Red Hat Enterprise Linux 4 Via RHSA-2009:1107 https://rhn.redhat.com/errata/RHSA-2009-1107.html
apr-util-1.2.12-7.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report.
apr-util-1.3.7-1.fc11 has been pushed to the Fedora 11 stable repository. If problems still persist, please make note of it in this bug report.
apr-util-1.3.7-1.fc10 has been pushed to the Fedora 10 stable repository. If problems still persist, please make note of it in this bug report.
This issue has been addressed in following products: JBEWS 1.0.0 for RHEL 4 Via RHSA-2009:1160 https://rhn.redhat.com/errata/RHSA-2009-1160.html
This issue has been addressed in following products: Red Hat Certificate System 7.3 Via RHSA-2010:0602 https://rhn.redhat.com/errata/RHSA-2010-0602.html