FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

apr -- multiple vunerabilities

Affected packages
apr1 < 1.4.2.1.3.10
apr0 < 0.9.19.0.9.19

Details

VuXML ID dd943fbb-d0fe-11df-95a8-00219b0fc4d8
Discovery 2010-10-02
Entry 2010-10-06
Modified 2010-10-20

Secunia reports:

Multiple vulnerabilities have been reported in APR-util, which can be exploited by malicious people to cause a DoS (Denial of Service).

Two XML parsing vulnerabilities exist in the bundled version of expat.

An error within the "apr_brigade_split_line()" function in buckets/apr_brigade.c can be exploited to cause high memory consumption.

References

Bugtraq ID 43673
CVE Name CVE-2009-3560
CVE Name CVE-2009-3720
CVE Name CVE-2010-1623
URL http://secunia.com/advisories/41701
URL http://www.apache.org/dist/apr/CHANGES-APR-UTIL-1.3