Apache Httpd CVE-2009-2412 Numeric Errors Vulnerability

description-logoDescription

A flaw in apr_palloc() in the bundled copy of APR could cause heap overflows in programs that try to apr_palloc() a user controlled size. The Apache HTTP Server itself does not pass unsanitized user-provided sizes to this function, so it could only be triggered through some other application which uses apr_palloc() in a vulnerable way.

affected-products-logoAffected Applications

Apache Httpd

CVE References

CVE-2009-2412