Referenced CVEs:
CVE-2009-2412
Description:
===========================================================Ubuntu Security Notice USN-813-3 August 08, 2009apr-util vulnerabilityCVE-2009-2412===========================================================A security issue affects the following Ubuntu releases:Ubuntu 8.04 LTSUbuntu 8.10Ubuntu 9.04This advisory also applies to the corresponding versions ofKubuntu, Edubuntu, and Xubuntu.The problem can be corrected by upgrading your system to thefollowing package versions:Ubuntu 8.04 LTS: libaprutil1 1.2.12+dfsg-3ubuntu0.2Ubuntu 8.10: libaprutil1 1.2.12+dfsg-7ubuntu0.3Ubuntu 9.04: libaprutil1 1.2.12+dfsg-8ubuntu0.3After a standard system upgrade you need to restart any applications usingapr-util, such as Subversion and Apache, to effect the necessary changes.Details follow:USN-813-1 fixed vulnerabilities in apr. This update provides the corresponding updates for apr-util.Original advisory details: Matt Lewis discovered that apr did not properly sanitize its input when allocating memory. If an application using apr processed crafted input, a remote attacker could cause a denial of service or potentially execute arbitrary code as the user invoking the application.
More...