CVE-2009-2411
published 2009-08-07CVE-2009-2411: Multiple integer overflows in the libsvn_delta library in Subversion before 1.5.7, and 1.6.x before 1.6.4, allow remote authenticated users and remote…
PriorityP343high8.5CVSS 2.0
AVNACMAuSCCICAC
EPSS
5.11%
91.4th percentile
Multiple integer overflows in the libsvn_delta library in Subversion before 1.5.7, and 1.6.x before 1.6.4, allow remote authenticated users and remote Subversion servers to execute arbitrary code via an svndiff stream with large windows that trigger a heap-based buffer overflow, a related issue to CVE-2009-2412.
Affected
70 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | subversion | — | — |
| apache | subversion | >= 0 < 1.6.4dfsg-1 | 1.6.4dfsg-1 |
| apache | subversion | >= 0 < 1.6.4dfsg-1 | 1.6.4dfsg-1 |
| apache | subversion | >= 0 < 1.6.4dfsg-1 | 1.6.4dfsg-1 |
| apache | subversion | >= 0 < 1.6.4dfsg-1 | 1.6.4dfsg-1 |
| debian | subversion | < subversion 1.6.4dfsg-1 (bookworm) | subversion 1.6.4dfsg-1 (bookworm) |
| subversion | subversion | <= 1.5.6 | — |
| subversion | subversion | — | — |
| subversion | subversion | — | — |
| subversion | subversion | — | — |
| subversion | subversion | — | — |
| subversion | subversion | — | — |
| subversion | subversion | — | — |
| subversion | subversion | — | — |
| subversion | subversion | — | — |
| subversion | subversion | — | — |
| subversion | subversion | — | — |
| subversion | subversion | — | — |
| subversion | subversion | — | — |
| subversion | subversion | — | — |
| subversion | subversion | — | — |
| subversion | subversion | — | — |
| subversion | subversion | — | — |
| subversion | subversion | — | — |
| subversion | subversion | — | — |
CVSS provenance
nvdv2.08.5HIGHAV:N/AC:M/Au:S/C:C/I:C/A:C
osv8.5HIGH
vendor_apache8.5HIGH
vendor_debian8.5HIGH
vendor_redhat8.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Subversion vulnerability
vendor_ubuntu·2009-08-08
CVE-2009-2411 Subversion vulnerability
Title: Subversion vulnerability
Summary: Subversion vulnerability
Matt Lewis discovered that Subversion did not properly sanitize its input
when processing svndiff streams, leading to various integer and heap
overflows. If a user or automated system processed crafted input, a remote
attacker could cause a denial of service or potentially execute arbitrary
code as the user processing the input.
Instructions: After a standard system upgrade you need to restart any applications that
use Subversion, such as Apache when using mod_dav_svn, to effect the
necessary changes.
Red Hat
subversion: multiple heap overflow issues
vendor_redhat·2009-08-03·CVSS 8.5
CVE-2009-2411 [HIGH] subversion: multiple heap overflow issues
subversion: multiple heap overflow issues
Multiple integer overflows in the libsvn_delta library in Subversion before 1.5.7, and 1.6.x before 1.6.4, allow remote authenticated users and remote Subversion servers to execute arbitrary code via an svndiff stream with large windows that trigger a heap-based buffer overflow, a related issue to CVE-2009-2412.
Debian
CVE-2009-2411: subversion - Multiple integer overflows in the libsvn_delta library in Subversion before 1.5....
vendor_debian·2009·CVSS 8.5
CVE-2009-2411 [HIGH] CVE-2009-2411: subversion - Multiple integer overflows in the libsvn_delta library in Subversion before 1.5....
Multiple integer overflows in the libsvn_delta library in Subversion before 1.5.7, and 1.6.x before 1.6.4, allow remote authenticated users and remote Subversion servers to execute arbitrary code via an svndiff stream with large windows that trigger a heap-based buffer overflow, a related issue to CVE-2009-2412.
Scope: local
bookworm: resolved (fixed in 1.6.4dfsg-1)
bullseye: resolved (fixed in 1.6.4dfsg-1)
forky: resolved (fixed in 1.6.4dfsg-1)
sid: resolved (fixed in 1.6.4dfsg-1)
trixie: resolved (fixed in 1.6.4dfsg-1)
Apache
Apache subversion: CVE-2009-2411
vendor_apache·CVSS 8.5
CVE-2009-2411 [HIGH] Apache subversion: CVE-2009-2411
Apache subversion: CVE-2009-2411
-advisory.txt 1.0.0-1.6.3 Heap Overflow in binary delta parser.
GHSA
GHSA-vmfg-4frj-fmfg: Multiple integer overflows in the libsvn_delta library in Subversion before 1
ghsa_unreviewed·2022-05-02·CVSS 10.0
CVE-2009-2411 [CRITICAL] GHSA-vmfg-4frj-fmfg: Multiple integer overflows in the libsvn_delta library in Subversion before 1
Multiple integer overflows in the libsvn_delta library in Subversion before 1.5.7, and 1.6.x before 1.6.4, allow remote authenticated users and remote Subversion servers to execute arbitrary code via an svndiff stream with large windows that trigger a heap-based buffer overflow, a related issue to CVE-2009-2412.
OSV
CVE-2009-2411: Multiple integer overflows in the libsvn_delta library in Subversion before 1
osv·2009-08-07·CVSS 8.5
CVE-2009-2411 [HIGH] CVE-2009-2411: Multiple integer overflows in the libsvn_delta library in Subversion before 1
Multiple integer overflows in the libsvn_delta library in Subversion before 1.5.7, and 1.6.x before 1.6.4, allow remote authenticated users and remote Subversion servers to execute arbitrary code via an svndiff stream with large windows that trigger a heap-based buffer overflow, a related issue to CVE-2009-2412.
No detection rules found.
No public exploits indexed.
http://archives.neohapsis.com/archives/bugtraq/2009-08/0056.htmlhttp://lists.apple.com/archives/security-announce/2009/Nov/msg00000.htmlhttp://osvdb.org/56856http://secunia.com/advisories/36184http://secunia.com/advisories/36224http://secunia.com/advisories/36232http://secunia.com/advisories/36257http://secunia.com/advisories/36262http://subversion.tigris.org/security/CVE-2009-2411-advisory.txthttp://support.apple.com/kb/HT3937http://svn.collab.net/repos/svn/tags/1.5.7/CHANGEShttp://svn.collab.net/repos/svn/tags/1.6.4/CHANGEShttp://svn.haxx.se/dev/archive-2009-08/0107.shtmlhttp://svn.haxx.se/dev/archive-2009-08/0108.shtmlhttp://svn.haxx.se/dev/archive-2009-08/0110.shtmlhttp://www.debian.org/security/2009/dsa-1855http://www.mandriva.com/security/advisories?name=MDVSA-2009:199http://www.redhat.com/support/errata/RHSA-2009-1203.htmlhttp://www.securityfocus.com/bid/35983http://www.securitytracker.com/id?1022697http://www.ubuntu.com/usn/usn-812-1http://www.vupen.com/english/advisories/2009/2180http://www.vupen.com/english/advisories/2009/3184https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11465https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00469.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-August/msg00485.htmlhttp://archives.neohapsis.com/archives/bugtraq/2009-08/0056.htmlhttp://lists.apple.com/archives/security-announce/2009/Nov/msg00000.htmlhttp://osvdb.org/56856http://secunia.com/advisories/36184http://secunia.com/advisories/36224http://secunia.com/advisories/36232http://secunia.com/advisories/36257http://secunia.com/advisories/36262http://subversion.tigris.org/security/CVE-2009-2411-advisory.txthttp://support.apple.com/kb/HT3937http://svn.collab.net/repos/svn/tags/1.5.7/CHANGEShttp://svn.collab.net/repos/svn/tags/1.6.4/CHANGEShttp://svn.haxx.se/dev/archive-2009-08/0107.shtmlhttp://svn.haxx.se/dev/archive-2009-08/0108.shtmlhttp://svn.haxx.se/dev/archive-2009-08/0110.shtmlhttp://www.debian.org/security/2009/dsa-1855http://www.mandriva.com/security/advisories?name=MDVSA-2009:199http://www.redhat.com/support/errata/RHSA-2009-1203.htmlhttp://www.securityfocus.com/bid/35983http://www.securitytracker.com/id?1022697http://www.ubuntu.com/usn/usn-812-1http://www.vupen.com/english/advisories/2009/2180http://www.vupen.com/english/advisories/2009/3184https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11465https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00469.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-August/msg00485.html
2009-08-07
Published