Jump to content

Advisories MDVSA-2009:195-1: apr


paul
 Share

Recommended Posts

A vulnerability has been identified and corrected in apr and apr-util:

 

Multiple integer overflows in the Apache Portable Runtime (APR)

library and the Apache Portable Utility library (aka APR-util)

0.9.x and 1.3.x allow remote attackers to cause a denial of service

(application crash) or possibly execute arbitrary code via vectors that

trigger crafted calls to the (1) allocator_alloc or (2) apr_palloc

function in memory/unix/apr_pools.c in APR; or crafted calls to

the (3) apr_rmm_malloc, (4) apr_rmm_calloc, or (5) apr_rmm_realloc

function in misc/apr_rmm.c in APR-util; leading to buffer overflows.

NOTE: some of these details are obtained from third party information

(CVE-2009-2412).

 

This update provides fixes for these vulnerabilities.

 

Update:

 

apr-util packages were missing for Mandriva Enterprise Server 5 i586,

this has been adressed with this update.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...