{"id":"DEBIAN-CVE-2009-0023","details":"The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-util before 1.3.5 allows remote attackers to cause a denial of service (daemon crash) via crafted input involving (1) a .htaccess file used with the Apache HTTP Server, (2) the SVNMasterURI directive in the mod_dav_svn module in the Apache HTTP Server, (3) the mod_apreq2 module for the Apache HTTP Server, or (4) an application that uses the libapreq2 library, which triggers a heap-based buffer underflow.","modified":"2026-09-22T16:47:29.525708239Z","published":"2009-06-08T01:00:00.530Z","upstream":["CVE-2009-0023"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2009-0023"}],"affected":[{"package":{"name":"apr-util","ecosystem":"Debian:12","purl":"pkg:deb/debian/apr-util?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.7+dfsg-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2009-0023.json"}},{"package":{"name":"apr-util","ecosystem":"Debian:13","purl":"pkg:deb/debian/apr-util?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.7+dfsg-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2009-0023.json"}},{"package":{"name":"apr-util","ecosystem":"Debian:14","purl":"pkg:deb/debian/apr-util?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.7+dfsg-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2009-0023.json"}}],"schema_version":"1.9.0"}