CVE-2009-1955The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, as demonstrated by a PROPFIND request, a similar issue to CVE-2003-1564.
CWE-776 · XML entity expansion
Working exploit published
A reviewed exploit catalogue carries this CVE. Somebody has published code a stranger can run.
CVSS E:P
| Index | Artifact | Stars | First seen |
|---|---|---|---|
| Exploit-DB | Apache mod_dav / svn - Remote Denial of Service | 2009-06-01 |
A Waratek agent blocks this today.
Applicable rule: Promoted to MITIGATED-BY-RASP (security rule): this CVE's weakness (CWE-776: XML Entity Expansion) can be mitigated by an ARMR xxe security rule that blocks this class of attack at the JVM level, without requiring a CVE-specific patch.
| Decided by | secure-rule-match : A vulnerability class already blocked by an ARMR security rule |
|---|---|
| Finding | Promoted to MITIGATED-BY-RASP (security rule): this CVE's weakness (CWE-776: XML Entity Expansion) can be mitigated by an ARMR xxe security rule that blocks this class of attack at the JVM level, without requiring a CVE-specific patch. |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2 metrics
VRT selects the newest version's highest entry and
publishes it as cvssScore, newest rather than largest because scores are not comparable
across versions, and highest rather than first because the first entry is frequently a CNA placeholder
scoring 0.0 over NVD's own analysis.
| Version | Score | Band | Vector | Assigner | Type | |
|---|---|---|---|---|---|---|
| CVSS 3.1 | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
NVD | Primary | published |
| CVSS 2.0 | 5.0 | no band published | AV:N/AC:L/Au:N/C:N/I:N/A:P |
NVD | Primary |
| Advisory | Type | Quarter | Products Oracle named in risk matrix |
|---|---|---|---|
| Oracle Critical Patch Update April 2013 ↗ | CPU | 2013-Q2 | Oracle Fusion Middleware / Web Listener (-) |
| Family | Component | Oracle's version cell (verbatim) | Indexed as |
|---|---|---|---|
| Oracle Fusion Middleware | Web Listener | - |
| Source | Vendor | Product | Scheme | Affected Versions |
|---|---|---|---|---|
| nvd | apache | apr-util | generic | < 1.3.7 |
| nvd | apache | http server | generic | ≥ 2.2.0 and < 2.2.12 |
| nvd | apple | mac os x | generic | < 10.6.2 |
| nvd | canonical | ubuntu linux | generic | 6.06 · 8.04 · 8.10 · 9.04 |
| nvd | debian | debian linux | generic | 4.0 |
| nvd | fedoraproject | fedora | generic | 9 · 10 · 11 |
| nvd | oracle | http server | generic | any version |
| nvd | suse | linux enterprise server | generic | 9 |
| URL | Tags |
|---|---|
| http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html | Mailing List, Third Party Advisory |
| http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html | Mailing List, Third Party Advisory |
| http://marc.info/?l=apr-dev&m=124396021826125&w=2 | Mailing List, Patch |
| http://marc.info/?l=bugtraq&m=129190899612998&w=2 | Mailing List |
| http://secunia.com/advisories/34724 | Broken Link, Third Party Advisory |
| http://secunia.com/advisories/35284 | Broken Link, Third Party Advisory |
| http://secunia.com/advisories/35360 | Broken Link, Third Party Advisory |
| http://secunia.com/advisories/35395 | Broken Link, Third Party Advisory |
| http://secunia.com/advisories/35444 | Broken Link, Third Party Advisory |
| http://secunia.com/advisories/35487 | Broken Link, Third Party Advisory |
| Published | 2009-06-08 | By the CVE Program. |
|---|---|---|
| NVD record modified | 2026-06-16 | NVD's own last-modified date for this record. |