apr-util: Integer overflows in memory pool (apr) and relocatable memory (apr-util) management
Published Aug 6, 2009
10.0
HIGHCVSS 2.0
EPSS 13.78%
Description
Multiple integer overflows in the Apache Portable Runtime (APR) library and the Apache Portable Utility library (aka APR-util) 0.9.x and 1.3.x allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger crafted calls to the (1) allocator_alloc or (2) apr_palloc function in memory/unix/apr_pools.c in APR; or crafted calls to the (3) apr_rmm_malloc, (4) apr_rmm_calloc, or (5) apr_rmm_realloc function in misc/apr_rmm.c in APR-util; leading to buffer overflows. NOTE: some of these details are obtained from third party information.
Affected products
No data.
- 0.9.1
- 0.9.2
- 0.9.2-dev
- 0.9.3
- 0.9.3-dev
- 0.9.4
- 0.9.5
- 0.9.6
- 0.9.7-dev
- 0.9.8
- 0.9.9
- 0.9.16
- 1.3.0
- 1.3.1
- 1.3.2
- 1.3.3
- 1.3.4
- 1.3.4-dev
- 1.3.5
- 1.3.6
- 1.3.6-dev
- 1.3.7
- 1.3.8
- 0.9.1
- 0.9.2
- 0.9.2-dev
- 0.9.3
- 0.9.3-dev
- 0.9.4
- 0.9.5
- 0.9.6
- 0.9.7
- 0.9.7-dev
- 0.9.8
- 0.9.9
- 0.9.16-dev
- 1.3.0
- 1.3.1
- 1.3.2
- 1.3.3
- 1.3.4
- 1.3.4-dev
- 1.3.5
- 1.3.6
- 1.3.6-dev
- 1.3.7
- 1.3.8
No data.
JBEWS 1.0 for RHEL 4
httpd22-0:2.2.10-24.1.ep5.el4
Fixed · RHSA-2009:1462
Red Hat Certificate System 7.3
ant-0:1.6.5-1jpp_1rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
avalon-logkit-0:1.2-2jpp_4rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
axis-0:1.2.1-1jpp_3rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
classpathx-jaf-0:1.0-2jpp_6rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
classpathx-mail-0:1.1.1-2jpp_8rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
geronimo-specs-0:1.0-0.M4.1jpp_10rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
jakarta-commons-modeler-0:2.0-3jpp_2rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
log4j-0:1.2.12-1jpp_1rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
mx4j-1:3.0.1-1jpp_4rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
pcsc-lite-0:1.3.3-3.el4
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
rhpki-ca-0:7.3.0-20.el4
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
rhpki-java-tools-0:7.3.0-10.el4
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
rhpki-kra-0:7.3.0-14.el4
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
rhpki-manage-0:7.3.0-19.el4
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
rhpki-native-tools-0:7.3.0-6.el4
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
rhpki-ocsp-0:7.3.0-13.el4
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
rhpki-tks-0:7.3.0-13.el4
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
tomcat5-0:5.5.23-0jpp_4rh.16
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
xerces-j2-0:2.7.1-1jpp_1rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
xml-commons-0:1.3.02-2jpp_1rh
Fixed · RHSA-2010:0602
Red Hat Enterprise Linux 3
httpd-0:2.0.46-75.ent
Fixed · RHSA-2009:1205
Red Hat Enterprise Linux 4
apr-0:0.9.4-24.9.el4_8.2
Fixed · RHSA-2009:1204
Red Hat Enterprise Linux 4
apr-util-0:0.9.4-22.el4_8.2
Fixed · RHSA-2009:1204
Red Hat Enterprise Linux 5
apr-0:1.2.7-11.el5_3.1
Fixed · RHSA-2009:1204
Red Hat Enterprise Linux 5
apr-util-0:1.2.7-7.el5_3.2
Fixed · RHSA-2009:1204
| Product | Package | State | Advisory |
|---|---|---|---|
| JBEWS 1.0 for RHEL 4 | httpd22-0:2.2.10-24.1.ep5.el4 | Fixed | RHSA-2009:1462 |
| Red Hat Certificate System 7.3 | ant-0:1.6.5-1jpp_1rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | avalon-logkit-0:1.2-2jpp_4rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | axis-0:1.2.1-1jpp_3rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | classpathx-jaf-0:1.0-2jpp_6rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | classpathx-mail-0:1.1.1-2jpp_8rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | geronimo-specs-0:1.0-0.M4.1jpp_10rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | jakarta-commons-modeler-0:2.0-3jpp_2rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | log4j-0:1.2.12-1jpp_1rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | mx4j-1:3.0.1-1jpp_4rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | pcsc-lite-0:1.3.3-3.el4 | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | rhpki-ca-0:7.3.0-20.el4 | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | rhpki-java-tools-0:7.3.0-10.el4 | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | rhpki-kra-0:7.3.0-14.el4 | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | rhpki-manage-0:7.3.0-19.el4 | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | rhpki-native-tools-0:7.3.0-6.el4 | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | rhpki-ocsp-0:7.3.0-13.el4 | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | rhpki-tks-0:7.3.0-13.el4 | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | tomcat5-0:5.5.23-0jpp_4rh.16 | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | xerces-j2-0:2.7.1-1jpp_1rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | xml-commons-0:1.3.02-2jpp_1rh | Fixed | RHSA-2010:0602 |
| Red Hat Enterprise Linux 3 | httpd-0:2.0.46-75.ent | Fixed | RHSA-2009:1205 |
| Red Hat Enterprise Linux 4 | apr-0:0.9.4-24.9.el4_8.2 | Fixed | RHSA-2009:1204 |
| Red Hat Enterprise Linux 4 | apr-util-0:0.9.4-22.el4_8.2 | Fixed | RHSA-2009:1204 |
| Red Hat Enterprise Linux 5 | apr-0:1.2.7-11.el5_3.1 | Fixed | RHSA-2009:1204 |
| Red Hat Enterprise Linux 5 | apr-util-0:1.2.7-7.el5_3.2 | Fixed | RHSA-2009:1204 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (56)
- http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html vendor-advisoryx_refsource_APPLE
- http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00006.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html vendor-advisoryx_refsource_SUSE
- http://osvdb.org/56765 vdb-entryx_refsource_OSVDB
- http://osvdb.org/56766 vdb-entryx_refsource_OSVDB
- http://secunia.com/advisories/36138 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/36140 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/36166 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/36233 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/37152 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/37221 third-party-advisoryx_refsource_SECUNIA
- http://support.apple.com/kb/HT3937 x_refsource_CONFIRM
- http://svn.apache.org/viewvc/apr/apr-util/branches/0.9.x/CHANGES?revision=800736&view=markup x_refsource_CONFIRMExploit
- http://svn.apache.org/viewvc/apr/apr-util/branches/0.9.x/misc/apr_rmm.c?r1=230441&r2=800736 x_refsource_CONFIRM
- http://svn.apache.org/viewvc/apr/apr-util/branches/1.3.x/CHANGES?revision=800735&view=markup x_refsource_CONFIRMExploit
- http://svn.apache.org/viewvc/apr/apr-util/branches/1.3.x/misc/apr_rmm.c?r1=647687&r2=800735 x_refsource_CONFIRM
- http://svn.apache.org/viewvc/apr/apr/branches/0.9.x/CHANGES?revision=800733&view=markup x_refsource_CONFIRM
- http://svn.apache.org/viewvc/apr/apr/branches/0.9.x/memory/unix/apr_pools.c?r1=585356&r2=800733 x_refsource_CONFIRMExploit
- http://svn.apache.org/viewvc/apr/apr/branches/1.3.x/CHANGES?revision=800732&view=markup x_refsource_CONFIRM
- http://svn.apache.org/viewvc/apr/apr/branches/1.3.x/memory/unix/apr_pools.c?r1=678140&r2=800732 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg1PK93225 vendor-advisoryx_refsource_AIXAPAR
- http://www-01.ibm.com/support/docview.wss?uid=swg1PK99482 vendor-advisoryx_refsource_AIXAPAR
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:195 vendor-advisoryx_refsource_MANDRIVA
- http://www.securityfocus.com/bid/35949 vdb-entryx_refsource_BIDPatch
- http://www.ubuntu.com/usn/usn-813-2 vendor-advisoryx_refsource_UBUNTU
- http://www.vupen.com/english/advisories/2009/3184 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2010/1107 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2009-2412 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=515698 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-2408 Advisory
- https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r2295080a257bad27ea68ca0af12fc715577f9e84801eae116a33107e%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rad2acee3ab838b52c04a0698b1728a9a43467bf365bd481c993c535d%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/reb7c64aeea604bf948467d9d1cab8ff23fa7d002be1964bcc275aae7%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://nvd.nist.gov/vuln/detail/CVE-2009-2412
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8394 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9958 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2009-2412
- https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00320.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00353.html vendor-advisoryx_refsource_FEDORA
Change history (0)
No recorded changes yet.