New User, Welcome!     Login

Matt Lewis

[USN-813-3] apr-util vulnerability

USN-813-1 fixed vulnerabilities in apr. This update provides the corresponding updates for apr-util.

Original advisory details:

 Matt Lewis discovered that apr did not properly sanitize its input when
 allocating memory. If an application using apr processed crafted input, a
 remote attacker could cause a denial of service or potentially execute
 arbitrary code as the user invoking the application.



[ GLSA 200909-03 ] Apache Portable Runtime, APR Utility Library: Execution of arbitrary code

    -------------------------------------------------------------------

Description
===========

Matt Lewis reported multiple Integer overflows in the apr_rmm_malloc(),
apr_rmm_calloc(), and apr_rmm_realloc() functions in misc/apr_rmm.c of
APR-Util and in memory/unix/apr_pools.c of APR, both occurring when
aligning memory blocks.

Impact

[USN-813-2] Apache vulnerability

USN-813-1 fixed vulnerabilities in apr. This update provides the
corresponding updates for apr as provided by Apache on Ubuntu 6.06 LTS.

Original advisory details:

 Matt Lewis discovered that apr did not properly sanitize its input when
 allocating memory. If an application using apr processed crafted input, a
 remote attacker could cause a denial of service or potentially execute
 arbitrary code as the user invoking the application.



[USN-813-1] apr vulnerability

After a standard system upgrade you need to restart any applications using
apr, such as Subversion and Apache, to effect the necessary changes.

Details follow:

Matt Lewis discovered that apr did not properly sanitize its input when
allocating memory. If an application using apr processed crafted input, a
remote attacker could cause a denial of service or potentially execute
arbitrary code as the user invoking the application.



Subversion heap overflow

  CVE-2009-2412  (APR)

Reported by:
============

  Matt Lewis, Google.

Patches:
========

  This patch applies to Subversion 1.6.x (apply with patch -p0 < patchfile):

[SECURITY] [DSA 1854-1] New APR packages fix arbitrary code execution

Package        : apr, apr-util
Vulnerability  : heap buffer overflow
Debian-specific: no
CVE Id(s)      : CVE-2009-2412

Matt Lewis discovered that the memory management code in the Apache
Portable Runtime (APR) library does not guard against a wrap-around
during size computations.  This could cause the library to return a
memory area which smaller than requested, resulting a heap overflow
and possibly arbitrary code execution.


[ GLSA 200908-05 ] Subversion: Remote execution of arbitrary code

  1  dev-util/subversion       < 1.6.4                        >= 1.6.4

Description
===========

Matt Lewis of Google reported multiple integer overflows in the
libsvn_delta library, possibly leading to heap-based buffer overflows.

Impact
======


[USN-812-1] Subversion vulnerability

use Subversion, such as Apache when using mod_dav_svn, to effect the
necessary changes.

Details follow:

Matt Lewis discovered that Subversion did not properly sanitize its input
when processing svndiff streams, leading to various integer and heap
overflows. If a user or automated system processed crafted input, a remote
attacker could cause a denial of service or potentially execute arbitrary
code as the user processing the input.


[SECURITY] [DSA 1855-1] New subversion packages fix arbitrary code execution

Vulnerability  : heap overflow
Problem type   : remote
Debian-specific: no
CVE Id(s)      : CVE-2009-2411

Matt Lewis discovered that Subversion performs insufficient input
validation of svndiff streams.  Malicious servers could cause heap
overflows in clients, and malicious clients with commit access could
cause heap overflows in servers, possibly leading to arbitrary code
execution in both cases.




Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!