Lucene search

K
freebsdFreeBSDEB9212F7-526B-11DE-BBF2-001B77D09812
HistoryJun 05, 2009 - 12:00 a.m.

apr -- multiple vulnerabilities

2009-06-0500:00:00
vuxml.freebsd.org
21

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:N/A:P

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.389

Percentile

97.3%

Secunia reports:

Some vulnerabilities have been reported in APR-util, which
can be exploited by malicious users and malicious people to
cause a DoS (Denial of Service).
A vulnerability is caused due to an error in the processing
of XML files and can be exploited to exhaust all available
memory via a specially crafted XML file containing a
predefined entity inside an entity definition.
A vulnerability is caused due to an error within the
“apr_strmatch_precompile()” function in
strmatch/apr_strmatch.c, which can be exploited to crash an
application using the library.

RedHat reports:

A single NULL byte buffer overflow flaw was found in
apr-util’s apr_brigade_vprintf() function.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchapr< 1.3.5.1.3.7UNKNOWN
FreeBSDanynoarchapache= 2.2.0UNKNOWN
FreeBSDanynoarchapache< 2.2.11_5UNKNOWN

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:N/A:P

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.389

Percentile

97.3%