The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-util before 1.3.5 allows remote attackers to cause a denial of service (daemon crash) via crafted input involving (1) a .htaccess file used with the Apache HTTP Server, (2) the SVNMasterURI directive in the mod_dav_svn module in the Apache HTTP Server, (3) the mod_apreq2 module for the Apache HTTP Server, or (4) an application that uses the libapreq2 library, which triggers a heap-based buffer underflow.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Httpd | — | Upgrade to the latest version of Apache HTTPD | Apr 12, 2012 | Jun 8, 2009 |
| Apple Osx Apache | — | Apply OS X security update 2009-006Upgrade macOS to the latest version | Dec 16, 2011 | Jun 7, 2009 |
| Apple Osx Apacheportableruntime | — | Apply OS X security update 2009-006Upgrade macOS to the latest version | Dec 16, 2011 | Jun 7, 2009 |
| Centos_linux | — | Upgrade apr-util-develUpgrade apr-util-docsUpgrade apr-util | Dec 1, 2016 | Jun 7, 2009 |
| Debian | — | Upgrade apr-util | Jul 30, 2024 | Jun 8, 2009 |
| Freebsd | — | Upgrade aprUpgrade apache | Dec 10, 2025 | Aug 25, 2009 |
| Gentoo Linux | — | Upgrade dev-libs/apr-util. | Oct 30, 2017 | Jun 7, 2009 |
| Hpux | — | Update hpuxwsAPCH32.AUTH_LDAP to the latest versionUpdate hpuxwsAPACHE.APACHE to the latest versionUpdate hpuxwsAPCH32.MOD_JK to the latest versionUpdate hpuxwsAPACHE.MOD_JK to the latest versionUpdate hpuxwsAPCH32.MOD_JK2 to the latest versionUpdate hpuxwsAPACHE.WEBPROXY to the latest versionUpdate hpuxwsAPACHE.MOD_JK2 to the latest versionUpdate hpuxwsAPCH32.WEBPROXY to the latest versionUpdate hpuxwsAPACHE.PHP2 to the latest versionUpdate hpuxwsAPCH32.MOD_PERL to the latest versionUpdate hpuxwsAPCH32.PHP2 to the latest versionUpdate hpuxwsAPACHE.MOD_PERL to the latest versionUpdate hpuxwsAPCH32.MOD_PERL2 to the latest versionUpdate hpuxwsAPCH32.APACHE2 to the latest versionUpdate hpuxwsAPACHE.AUTH_LDAP2 to the latest versionUpdate hpuxwsAPCH32.PHP to the latest versionUpdate hpuxwsAPACHE.MOD_PERL2 to the latest versionUpdate hpuxwsAPACHE.PHP to the latest versionUpdate hpuxwsAPACHE.APACHE2 to the latest versionUpdate hpuxwsAPCH32.APACHE to the latest versionUpdate hpuxwsAPACHE.AUTH_LDAP to the latest versionUpdate hpuxwsAPCH32.AUTH_LDAP2 to the latest version | Aug 11, 2017 | Jun 7, 2009 |
| Oracle_linux | — | Upgrade apr-utilUpgrade apr-util-docsUpgrade apr-util-devel | Oct 16, 2024 | Jun 6, 2009 |
| Suse | — | Upgrade apache2-eventUpgrade apache2-docUpgrade apache2-example-pagesUpgrade libapr-util1-dbd-mysqlUpgrade libapr-util1-0-dbd-mysqlUpgrade libapr-util1-0Upgrade libapr-util1-develUpgrade apache2-utilsUpgrade libapr-util1-32bitUpgrade libapr-util1-dbd-pgsqlUpgrade apache2-preforkUpgrade apr-util-develUpgrade apache2-manualUpgrade libapr-util1-0-dbd-pgsqlUpgrade apache2-workerUpgrade libapr-util1-0-dbd-sqlite3Upgrade libapr1-32bitUpgrade libapr-util1-dbd-sqlite3Upgrade libapr1Upgrade apache2Upgrade libapr-util1Upgrade apache2-devel | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libaprutil1Upgrade apache2-mpm-perchildUpgrade apache2-mpm-workerUpgrade libapr0Upgrade apache2-mpm-preforkUpgrade apache2-common | Nov 8, 2024 | Jun 8, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub