CVE-2009-2411

Multiple integer overflows in the libsvn_delta library in Subversion before 1.5.7, and 1.6.x before 1.6.4, allow remote authenticated users and remote Subversion servers to execute arbitrary code via an svndiff stream with large windows that trigger a heap-based buffer overflow, a related issue to CVE-2009-2412.
References
Link Resource
http://archives.neohapsis.com/archives/bugtraq/2009-08/0056.html
http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html
http://osvdb.org/56856
http://secunia.com/advisories/36184 Vendor Advisory
http://secunia.com/advisories/36224
http://secunia.com/advisories/36232
http://secunia.com/advisories/36257
http://secunia.com/advisories/36262
http://subversion.tigris.org/security/CVE-2009-2411-advisory.txt
http://support.apple.com/kb/HT3937
http://svn.collab.net/repos/svn/tags/1.5.7/CHANGES
http://svn.collab.net/repos/svn/tags/1.6.4/CHANGES
http://svn.haxx.se/dev/archive-2009-08/0107.shtml
http://svn.haxx.se/dev/archive-2009-08/0108.shtml
http://svn.haxx.se/dev/archive-2009-08/0110.shtml
http://www.debian.org/security/2009/dsa-1855
http://www.mandriva.com/security/advisories?name=MDVSA-2009:199
http://www.redhat.com/support/errata/RHSA-2009-1203.html
http://www.securityfocus.com/bid/35983
http://www.securitytracker.com/id?1022697
http://www.ubuntu.com/usn/usn-812-1
http://www.vupen.com/english/advisories/2009/2180 Vendor Advisory
http://www.vupen.com/english/advisories/2009/3184
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11465
https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00469.html
https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00485.html
http://archives.neohapsis.com/archives/bugtraq/2009-08/0056.html
http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html
http://osvdb.org/56856
http://secunia.com/advisories/36184 Vendor Advisory
http://secunia.com/advisories/36224
http://secunia.com/advisories/36232
http://secunia.com/advisories/36257
http://secunia.com/advisories/36262
http://subversion.tigris.org/security/CVE-2009-2411-advisory.txt
http://support.apple.com/kb/HT3937
http://svn.collab.net/repos/svn/tags/1.5.7/CHANGES
http://svn.collab.net/repos/svn/tags/1.6.4/CHANGES
http://svn.haxx.se/dev/archive-2009-08/0107.shtml
http://svn.haxx.se/dev/archive-2009-08/0108.shtml
http://svn.haxx.se/dev/archive-2009-08/0110.shtml
http://www.debian.org/security/2009/dsa-1855
http://www.mandriva.com/security/advisories?name=MDVSA-2009:199
http://www.redhat.com/support/errata/RHSA-2009-1203.html
http://www.securityfocus.com/bid/35983
http://www.securitytracker.com/id?1022697
http://www.ubuntu.com/usn/usn-812-1
http://www.vupen.com/english/advisories/2009/2180 Vendor Advisory
http://www.vupen.com/english/advisories/2009/3184
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11465
https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00469.html
https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00485.html
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:subversion:subversion:*:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:0.22.1:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:0.23.0:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:0.24.0:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:0.24.1:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:0.24.2:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:0.25.0:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:0.27.0:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:0.28.0:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:0.28.1:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:0.28.2:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:0.29.0:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:0.30.0:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:0.31.0:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:0.32.0:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:0.32.1:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:0.33.0:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:0.33.1:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:0.34.0:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:0.35.0:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:0.35.1:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:0.36.0:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:0.37.0:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.0:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.0.3:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.0.4:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.0.5:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.0.6:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.0.7:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.0.8:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.0.9:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.1.0_rc1:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.1.0_rc2:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.1.0_rc3:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.1.1:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.1.2:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.1.3:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.1.4:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.2.2:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.2.3:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.3.0:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.3.1:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.3.2:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.4.1:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.4.2:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.4.3:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.4.4:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.4.5:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.5.0:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.5.1:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.5.3:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.5.4:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.5.5:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.6.0:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.6.1:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.6.2:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.6.3:*:*:*:*:*:*:*

History

21 Nov 2024, 01:04

Type Values Removed Values Added
References () http://archives.neohapsis.com/archives/bugtraq/2009-08/0056.html - () http://archives.neohapsis.com/archives/bugtraq/2009-08/0056.html -
References () http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html - () http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html -
References () http://osvdb.org/56856 - () http://osvdb.org/56856 -
References () http://secunia.com/advisories/36184 - Vendor Advisory () http://secunia.com/advisories/36184 - Vendor Advisory
References () http://secunia.com/advisories/36224 - () http://secunia.com/advisories/36224 -
References () http://secunia.com/advisories/36232 - () http://secunia.com/advisories/36232 -
References () http://secunia.com/advisories/36257 - () http://secunia.com/advisories/36257 -
References () http://secunia.com/advisories/36262 - () http://secunia.com/advisories/36262 -
References () http://subversion.tigris.org/security/CVE-2009-2411-advisory.txt - () http://subversion.tigris.org/security/CVE-2009-2411-advisory.txt -
References () http://support.apple.com/kb/HT3937 - () http://support.apple.com/kb/HT3937 -
References () http://svn.collab.net/repos/svn/tags/1.5.7/CHANGES - () http://svn.collab.net/repos/svn/tags/1.5.7/CHANGES -
References () http://svn.collab.net/repos/svn/tags/1.6.4/CHANGES - () http://svn.collab.net/repos/svn/tags/1.6.4/CHANGES -
References () http://svn.haxx.se/dev/archive-2009-08/0107.shtml - () http://svn.haxx.se/dev/archive-2009-08/0107.shtml -
References () http://svn.haxx.se/dev/archive-2009-08/0108.shtml - () http://svn.haxx.se/dev/archive-2009-08/0108.shtml -
References () http://svn.haxx.se/dev/archive-2009-08/0110.shtml - () http://svn.haxx.se/dev/archive-2009-08/0110.shtml -
References () http://www.debian.org/security/2009/dsa-1855 - () http://www.debian.org/security/2009/dsa-1855 -
References () http://www.mandriva.com/security/advisories?name=MDVSA-2009:199 - () http://www.mandriva.com/security/advisories?name=MDVSA-2009:199 -
References () http://www.redhat.com/support/errata/RHSA-2009-1203.html - () http://www.redhat.com/support/errata/RHSA-2009-1203.html -
References () http://www.securityfocus.com/bid/35983 - () http://www.securityfocus.com/bid/35983 -
References () http://www.securitytracker.com/id?1022697 - () http://www.securitytracker.com/id?1022697 -
References () http://www.ubuntu.com/usn/usn-812-1 - () http://www.ubuntu.com/usn/usn-812-1 -
References () http://www.vupen.com/english/advisories/2009/2180 - Vendor Advisory () http://www.vupen.com/english/advisories/2009/2180 - Vendor Advisory
References () http://www.vupen.com/english/advisories/2009/3184 - () http://www.vupen.com/english/advisories/2009/3184 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11465 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11465 -
References () https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00469.html - () https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00469.html -
References () https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00485.html - () https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00485.html -

Information

Published : 2009-08-07 19:30

Updated : 2024-11-21 01:04


NVD link : CVE-2009-2411

Mitre link : CVE-2009-2411

CVE.ORG link : CVE-2009-2411


JSON object : View

Products Affected

subversion

  • subversion
CWE
CWE-189

Numeric Errors