The expat XML parser in the apr_xml_* interface in xml...
Moderate severity
Unreviewed
Published
May 2, 2022
to the GitHub Advisory Database
•
Updated Feb 11, 2024
Description
Published by the National Vulnerability Database
Jun 8, 2009
Published to the GitHub Advisory Database
May 2, 2022
Last updated
Feb 11, 2024
The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, as demonstrated by a PROPFIND request, a similar issue to CVE-2003-1564.
References