The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, as demonstrated by a PROPFIND request, a similar issue to CVE-2003-1564.
Project Subscriptions
Advisories
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T05:36:19.503Z
Reserved: 2009-06-06T00:00:00
Link: CVE-2009-1955
No data.
Status : Deferred
Published: 2009-06-08T01:00:00.687
Modified: 2025-04-09T00:30:58.490
Link: CVE-2009-1955
OpenCVE Enrichment
No data.
Weaknesses
Ubuntu USN