CVE-2009-1955

HIGH

Apache APR-util < 1.3.7 - Denial of Service via XML Entity Expansion

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-1955. PoCs published by kingcope.

AI-analyzed exploit summary This exploit targets CVE-2009-1955, a denial-of-service vulnerability in Apache mod_dav and Subversion servers. It sends a maliciously crafted PROPFIND request with an XML bomb payload to exhaust system memory.

Description

The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, as demonstrated by a PROPFIND request, a similar issue to CVE-2003-1564.

Exploits (1)

exploitdb WORKING POC VERIFIED
by kingcope · perldosmultiple
https://www.exploit-db.com/exploits/8842

This exploit targets CVE-2009-1955, a denial-of-service vulnerability in Apache mod_dav and Subversion servers. It sends a maliciously crafted PROPFIND request with an XML bomb payload to exhaust system memory.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Apache mod_dav, Subversion (svn)
Auth required
Prerequisites: Network access to target server · WebDAV or Subversion service running · Optional authentication credentials if required
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (60)

Core 60
Core References
Broken Link, Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/1907
Broken Link, Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35487
Mailing List, Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2009/dsa-1812
Broken Link x_refsource_confirm
http://www.apache.org/dist/apr/CHANGES-APR-UTIL-1.3
Broken Link, Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35444
Mailing List, Patch mailing-list x_refsource_mlist
http://marc.info/?l=apr-dev&m=124396021826125&w=2
Broken Link, Third Party Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2009:131
Broken Link, Third Party Advisory vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10270
Broken Link, Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35360
Broken Link, Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/1107
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2009/06/03/4
Broken Link, Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35395
Broken Link, Third Party Advisory vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1PK99478
Broken Link, Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/506053/100/0/threaded
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html
Broken Link, Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35284
Broken Link, Third Party Advisory vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1PK91241
Broken Link, Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/36473
Broken Link vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1PK88342
Broken Link, Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35843
Broken Link, Third Party Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2009-1108.html
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=129190899612998&w=2
Broken Link, Third Party Advisory vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12473
Broken Link, Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35797
Patch, Third Party Advisory x_refsource_confirm
http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200907-03.xml
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-786-1
Broken Link, Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34724
Broken Link, Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/37221
Broken Link, Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35565
Broken Link, Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/3184
Broken Link x_refsource_confirm
http://wiki.rpath.com/Advisories:rPSA-2009-0123
Exploit, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/8842
Broken Link, Third Party Advisory vendor-advisory x_refsource_slackware
http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.538210
Broken Link, Third Party Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg27014463
Mailing List, Third Party Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html
Broken Link, Third Party Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2013:150
Broken Link, Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35710
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/35253
Broken Link, Third Party Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2009-1107.html
Broken Link x_refsource_confirm
http://support.apple.com/kb/HT3937
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-787-1

Scores

CVSS v3 7.5
EPSS 0.5327
EPSS Percentile 98.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-776
Status published
Products (13)
apache/apr-util < 1.3.7
apache/http_server 2.2.0 - 2.2.12
apple/mac_os_x < 10.6.2
canonical/ubuntu_linux 6.06
canonical/ubuntu_linux 8.04
canonical/ubuntu_linux 8.10
canonical/ubuntu_linux 9.04
debian/debian_linux 4.0
fedoraproject/fedora 9
fedoraproject/fedora 10
... and 3 more
Published Jun 08, 2009
Tracked Since Feb 18, 2026