5
CVSSv2

CVE-2009-5024

Published: 23/05/2011 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

ViewVC prior to 1.1.11 allows remote malicious users to bypass the cvsdb row_limit configuration setting, and consequently conduct resource-consumption attacks, via the limit parameter, as demonstrated by a "query revision history" request.

Vulnerable Product Search on Vulmon Subscribe to Product

viewvc viewvc 1.1.6

viewvc viewvc 1.0.2

viewvc viewvc 1.1.7

viewvc viewvc 1.0.1

viewvc viewvc 1.1.5

viewvc viewvc 0.8

viewvc viewvc 0.9.3

viewvc viewvc 1.0.5

viewvc viewvc 1.1.2

viewvc viewvc 0.9.2

viewvc viewvc 1.0.11

viewvc viewvc 1.0.9

viewvc viewvc 1.1.0

viewvc viewvc 1.1.1

viewvc viewvc 0.9.1

viewvc viewvc 1.1.4

viewvc viewvc 0.9.4

viewvc viewvc 1.1.8

viewvc viewvc 1.0.3

viewvc viewvc 1.0.4

viewvc viewvc 1.0.6

viewvc viewvc 1.0.8

viewvc viewvc

viewvc viewvc 1.0.10

viewvc viewvc 1.1.9

viewvc viewvc 1.0.0

viewvc viewvc 1.0.7

viewvc viewvc 1.1.3

viewvc viewvc 0.9

Vendor Advisories

Debian Bug report logs - #671482 CVE-2009-5024: Possible excessive resource use when commit database feature enabled Package: viewvc; Maintainer for viewvc is Lev Lamberov <dogsleg@debianorg>; Source for viewvc is src:viewvc (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <muehlenhoff@univentionde> Date: Fri, ...
Debian Bug report logs - #679069 CVE-2012-3356 / CVE-2012-3357 Package: viewvc; Maintainer for viewvc is Lev Lamberov <dogsleg@debianorg>; Source for viewvc is src:viewvc (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <muehlenhoff@univentionde> Date: Tue, 26 Jun 2012 07:45:11 UTC Severity: grave Tags: patch ...