The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, as demonstrated by a PROPFIND request, a similar issue to CVE-2003-1564.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Httpd | — | Upgrade to the latest version of Apache HTTPD | Apr 12, 2012 | Jun 8, 2009 |
| Apple Osx Apache | — | Apply OS X security update 2009-006Upgrade macOS to the latest version | Dec 16, 2011 | Jun 7, 2009 |
| Apple Osx Apacheportableruntime | — | Upgrade macOS to the latest versionApply OS X security update 2009-006 | Dec 16, 2011 | Jun 7, 2009 |
| Centos_linux | — | Upgrade apr-util-develUpgrade apr-util-docsUpgrade apr-util | Dec 1, 2016 | Jun 7, 2009 |
| Debian | — | Upgrade apr-util | Jul 30, 2024 | Jun 8, 2009 |
| Freebsd | — | Upgrade aprUpgrade apache | Dec 10, 2025 | Aug 25, 2009 |
| Gentoo Linux | — | Upgrade dev-libs/apr-util. | Oct 30, 2017 | Jun 7, 2009 |
| Hpux | — | Update hpuxwsAPACHE.MOD_PERL2 to the latest versionUpdate hpuxwsAPCH32.PHP2 to the latest versionUpdate hpuxwsAPACHE.AUTH_LDAP to the latest versionUpdate hpuxwsAPCH32.PHP to the latest versionUpdate hpuxwsAPCH32.APACHE to the latest versionUpdate hpuxwsAPACHE.APACHE2 to the latest versionUpdate hpuxwsAPCH32.APACHE2 to the latest versionUpdate hpuxwsAPACHE.AUTH_LDAP2 to the latest versionUpdate hpuxwsAPACHE.MOD_JK2 to the latest versionUpdate hpuxwsAPACHE.PHP to the latest versionUpdate hpuxwsAPCH32.MOD_JK2 to the latest versionUpdate hpuxwsAPCH32.AUTH_LDAP to the latest versionUpdate hpuxwsAPCH32.MOD_PERL to the latest versionUpdate hpuxwsAPCH32.WEBPROXY to the latest versionUpdate hpuxwsAPACHE.PHP2 to the latest versionUpdate hpuxwsAPACHE.MOD_PERL to the latest versionUpdate hpuxwsAPACHE.APACHE to the latest versionUpdate hpuxwsAPACHE.MOD_JK to the latest versionUpdate hpuxwsAPCH32.MOD_PERL2 to the latest versionUpdate hpuxwsAPCH32.AUTH_LDAP2 to the latest versionUpdate hpuxwsAPCH32.MOD_JK to the latest versionUpdate hpuxwsAPACHE.WEBPROXY to the latest version | Aug 11, 2017 | Jun 7, 2009 |
| Oracle_linux | — | Upgrade apr-util-develUpgrade apr-utilUpgrade apr-util-docs | Oct 16, 2024 | Jun 6, 2009 |
| Suse | — | Upgrade apache2-workerUpgrade libapr1Upgrade apache2Upgrade apache2-eventUpgrade apache2-utilsUpgrade apache2-develUpgrade libapr-util1-32bitUpgrade apache2-example-pagesUpgrade libapr1-32bitUpgrade libapr-util1Upgrade apache2-preforkUpgrade apache2-docUpgrade apache2-manual | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade apache2-commonUpgrade libaprutil1Upgrade apache2-mpm-preforkUpgrade apache2-mpm-workerUpgrade libapr0Upgrade apache2-mpm-perchild | Nov 8, 2024 | Jun 8, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub