Description
Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via crafted input.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2009-1951 | Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via crafted input. |
Ubuntu USN |
USN-786-1 | apr-util vulnerabilities |
Ubuntu USN |
USN-787-1 | Apache vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T05:36:19.492Z
Reserved: 2009-06-06T00:00:00.000Z
Link: CVE-2009-1956
No data.
Status : Modified
Published: 2009-06-08T01:00:00.703
Modified: 2026-04-23T00:35:47.467
Link: CVE-2009-1956
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Ubuntu USN