8.5
CVSSv2

CVE-2009-2411

Published: 07/08/2009 Updated: 19/09/2017
CVSS v2 Base Score: 8.5 | Impact Score: 10 | Exploitability Score: 6.8
VMScore: 756
Vector: AV:N/AC:M/Au:S/C:C/I:C/A:C

Vulnerability Summary

Multiple integer overflows in the libsvn_delta library in Subversion prior to 1.5.7, and 1.6.x prior to 1.6.4, allow remote authenticated users and remote Subversion servers to execute arbitrary code via an svndiff stream with large windows that trigger a heap-based buffer overflow, a related issue to CVE-2009-2412.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

subversion subversion 1.0.7

subversion subversion 1.0.1

subversion subversion 1.4.4

subversion subversion 1.5.3

subversion subversion 1.4.2

subversion subversion 1.3.1

subversion subversion 1.3.0

subversion subversion 1.2.3

subversion subversion 1.1.1

subversion subversion 1.0.9

subversion subversion 0.36.0

subversion subversion 0.34.0

subversion subversion 0.28.2

subversion subversion 0.28.1

subversion subversion 0.23.0

subversion subversion 0.22.1

subversion subversion 1.0.6

subversion subversion 1.0.5

subversion subversion 1.0.4

subversion subversion 1.4.3

subversion subversion 1.1.0_rc3

subversion subversion 1.5.1

subversion subversion 1.5.0

subversion subversion 1.2.1

subversion subversion 1.2.2

subversion subversion 1.1.0

subversion subversion 1.0.8

subversion subversion 0.33.1

subversion subversion 0.33.0

subversion subversion 0.28.0

subversion subversion 0.27.0

subversion subversion 1.6.3

subversion subversion 1.6.2

subversion subversion 1.0.3

subversion subversion 1.0

subversion subversion 1.5.5

subversion subversion 1.5.4

subversion subversion 1.4.0

subversion subversion 1.3.2

subversion subversion 1.1.3

subversion subversion 1.1.2

subversion subversion 0.35.1

subversion subversion 0.35.0

subversion subversion 0.31.0

subversion subversion 0.30.0

subversion subversion 0.29.0

subversion subversion 0.24.2

subversion subversion 0.24.0

subversion subversion 1.1.0_rc1

subversion subversion 1.0.2

subversion subversion 1.1.0_rc2

subversion subversion

subversion subversion 1.4.5

subversion subversion 1.4.1

subversion subversion 1.2.0

subversion subversion 1.1.4

subversion subversion 1.0.0

subversion subversion 0.37.0

subversion subversion 0.32.1

subversion subversion 0.32.0

subversion subversion 0.25.0

subversion subversion 0.24.1

subversion subversion 1.6.1

subversion subversion 1.6.0

Vendor Advisories

Matt Lewis discovered that Subversion did not properly sanitize its input when processing svndiff streams, leading to various integer and heap overflows If a user or automated system processed crafted input, a remote attacker could cause a denial of service or potentially execute arbitrary code as the user processing the input ...