Mandriva Linux Security Advisory : apr (MDVSA-2009:314)

Critical Nessus Plugin ID 43000

Synopsis

The remote Mandriva Linux host is missing one or more security updates.

Description

Multiple security vulnerabilities has been identified and fixed in apr and apr-util :

Multiple integer overflows in the Apache Portable Runtime (APR) library and the Apache Portable Utility library (aka APR-util) 0.9.x and 1.3.x allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger crafted calls to the (1) allocator_alloc or (2) apr_palloc function in memory/unix/apr_pools.c in APR; or crafted calls to the (3) apr_rmm_malloc, (4) apr_rmm_calloc, or (5) apr_rmm_realloc function in misc/apr_rmm.c in APR-util; leading to buffer overflows. NOTE: some of these details are obtained from third-party information (CVE-2009-2412).

The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-util before 1.3.5 allows remote attackers to cause a denial of service (daemon crash) via crafted input involving (1) a .htaccess file used with the Apache HTTP Server, (2) the SVNMasterURI directive in the mod_dav_svn module in the Apache HTTP Server, (3) the mod_apreq2 module for the Apache HTTP Server, or (4) an application that uses the libapreq2 library, related to an underflow flaw.
(CVE-2009-0023).

The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, as demonstrated by a PROPFIND request, a similar issue to CVE-2003-1564 (CVE-2009-1955).

Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via crafted input (CVE-2009-1956).

Packages for 2008.0 are provided for Corporate Desktop 2008.0 customers

The updated packages have been patched to prevent this.

Solution

Update the affected packages.

Plugin Details

Severity: Critical

ID: 43000

File Name: mandriva_MDVSA-2009-314.nasl

Version: 1.19

Type: local

Published: 2009/12/04

Updated: 2018/07/19

Dependencies: 12634

Risk Information

Risk Factor: Critical

CVSS v2.0

Base Score: 10

Temporal Score: 8.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:ND/RL:OF/RC:C

Vulnerability Information

CPE: p-cpe:/a:mandriva:linux:apr-util-dbd-mysql, p-cpe:/a:mandriva:linux:apr-util-dbd-pgsql, p-cpe:/a:mandriva:linux:apr-util-dbd-sqlite3, p-cpe:/a:mandriva:linux:lib64apr-devel, p-cpe:/a:mandriva:linux:lib64apr-util-devel, p-cpe:/a:mandriva:linux:lib64apr-util1, p-cpe:/a:mandriva:linux:lib64apr1, p-cpe:/a:mandriva:linux:libapr-devel, p-cpe:/a:mandriva:linux:libapr-util-devel, p-cpe:/a:mandriva:linux:libapr-util1, p-cpe:/a:mandriva:linux:libapr1, cpe:/o:mandriva:linux:2008.0

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list

Exploit Available: false

Exploit Ease: No known exploits are available

Patch Publication Date: 2009/12/04

Reference Information

CVE: CVE-2009-0023, CVE-2009-1955, CVE-2009-1956, CVE-2009-2412

BID: 35221, 35251, 35253, 35949

MDVSA: 2009:314

CWE: 119, 189, 399