CVE-2009-2412

NameCVE-2009-2412
DescriptionMultiple integer overflows in the Apache Portable Runtime (APR) library and the Apache Portable Utility library (aka APR-util) 0.9.x and 1.3.x allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger crafted calls to the (1) allocator_alloc or (2) apr_palloc function in memory/unix/apr_pools.c in APR; or crafted calls to the (3) apr_rmm_malloc, (4) apr_rmm_calloc, or (5) apr_rmm_realloc function in misc/apr_rmm.c in APR-util; leading to buffer overflows. NOTE: some of these details are obtained from third party information.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-1854-1
NVD severityhigh (attack range: remote)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
apr (PTS)wheezy1.4.6-3+deb7u1fixed
wheezy (security)1.4.6-3+deb7u2fixed
jessie1.5.1-3fixed
stretch1.5.2-5fixed
buster, sid1.6.3-1fixed
apr-util (PTS)wheezy1.4.1-3fixed
wheezy (security)1.4.1-3+deb7u1fixed
jessie1.5.4-1fixed
stretch1.5.4-3fixed
buster, sid1.6.1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
aprsource(unstable)1.3.8-1high
aprsourceetch1.2.7-9highDSA-1854-1
aprsourcelenny1.2.12-5+lenny1highDSA-1854-1
apr-utilsource(unstable)1.3.9+dfsg-1high
apr-utilsourceetch1.2.7+dfsg-2+etch3highDSA-1854-1
apr-utilsourcelenny1.2.12+dfsg-8+lenny4highDSA-1854-1

Search for package or bug name: Reporting problems