← All CVEs

CVE-2009-1955

high · 7.5

The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, as demonstrated by a PROPFIND request, a similar issue to CVE-2003-1564.

7.5
CVSS
53.0%
EPSS (exploit prob.)
99th
EPSS percentile
2009-06-08
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses

CWE-776

Affected products

VendorProductAffected versions
apacheapr-util< 1.3.7
applemac_os_x< 10.6.2
suselinux_enterprise_server9
debiandebian_linux4.0
canonicalubuntu_linux6.06
canonicalubuntu_linux8.04
canonicalubuntu_linux8.10
canonicalubuntu_linux9.04
fedoraprojectfedora9
fedoraprojectfedora10
fedoraprojectfedora11
oraclehttp_serverall versions
apachehttp_server>= 2.2.0, < 2.2.12

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2009-1955