← All CVEs

CVE-2009-2412

high · 10

Multiple integer overflows in the Apache Portable Runtime (APR) library and the Apache Portable Utility library (aka APR-util) 0.9.x and 1.3.x allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger crafted calls to the (1) allocator_alloc or (2) apr_palloc function in memory/unix/apr_pools.c in APR; or crafted calls to the (3) apr_rmm_malloc, (4) apr_rmm_calloc, or (5) apr_rmm_realloc function in misc/apr_rmm.c in APR-util; leading to buffer overflows. NOTE: some of these details are obtained from third party information.

10
CVSS
13.8%
EPSS (exploit prob.)
96th
EPSS percentile
2009-08-06
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

CWE-189

Affected products

VendorProductAffected versions
apacheapr-util0.9.1
apacheapr-util0.9.2
apacheapr-util0.9.2-dev
apacheapr-util0.9.3
apacheapr-util0.9.3-dev
apacheapr-util0.9.4
apacheapr-util0.9.5
apacheapr-util0.9.6
apacheapr-util0.9.7-dev
apacheapr-util0.9.8
apacheapr-util0.9.9
apacheapr-util0.9.16
apacheapr-util1.3.0
apacheapr-util1.3.1
apacheapr-util1.3.2
apacheapr-util1.3.3
apacheapr-util1.3.4
apacheapr-util1.3.4-dev
apacheapr-util1.3.5
apacheapr-util1.3.6
apacheapr-util1.3.6-dev
apacheapr-util1.3.7
apacheapr-util1.3.8
apacheportable_runtime0.9.1
apacheportable_runtime0.9.2
apacheportable_runtime0.9.2-dev
apacheportable_runtime0.9.3
apacheportable_runtime0.9.3-dev
apacheportable_runtime0.9.4
apacheportable_runtime0.9.5
apacheportable_runtime0.9.6
apacheportable_runtime0.9.7
apacheportable_runtime0.9.7-dev
apacheportable_runtime0.9.8
apacheportable_runtime0.9.9
apacheportable_runtime0.9.16-dev
apacheportable_runtime1.3.0
apacheportable_runtime1.3.1
apacheportable_runtime1.3.2
apacheportable_runtime1.3.3

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2009-2412