Lucene search

K
cveMitreCVE-2009-0537
HistoryMar 09, 2009 - 9:30 p.m.

CVE-2009-0537

2009-03-0921:30:00
CWE-189
mitre
web.nvd.nist.gov
117
cve-2009-0537
integer overflow
fts_build
libc
denial of service
openbsd
microsoft interix 6.0
nvd

CVSS2

4.9

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:N/I:N/A:C

AI Score

6.4

Confidence

Low

EPSS

0.002

Percentile

52.1%

Integer overflow in the fts_build function in fts.c in libc in (1) OpenBSD 4.4 and earlier and (2) Microsoft Interix 6.0 build 10.0.6030.0 allows context-dependent attackers to cause a denial of service (application crash) via a deep directory tree, related to the fts_level structure member, as demonstrated by (a) du, (b) rm, © chmod, and (d) chgrp on OpenBSD; and (e) SearchIndexer.exe on Vista Enterprise.

Affected configurations

Nvd
Node
microsoftinterixMatch6.010.0.6030.0
OR
openbsdopenbsdRange4.4
OR
openbsdopenbsdMatch2.0
OR
openbsdopenbsdMatch2.1
OR
openbsdopenbsdMatch2.2
OR
openbsdopenbsdMatch2.3
OR
openbsdopenbsdMatch2.4
OR
openbsdopenbsdMatch2.5
OR
openbsdopenbsdMatch2.6
OR
openbsdopenbsdMatch2.7
OR
openbsdopenbsdMatch2.8
OR
openbsdopenbsdMatch2.9
OR
openbsdopenbsdMatch3.0
OR
openbsdopenbsdMatch3.1
OR
openbsdopenbsdMatch3.2
OR
openbsdopenbsdMatch3.3
OR
openbsdopenbsdMatch3.4
OR
openbsdopenbsdMatch3.5
OR
openbsdopenbsdMatch3.6
OR
openbsdopenbsdMatch3.7
OR
openbsdopenbsdMatch3.8
OR
openbsdopenbsdMatch3.9
OR
openbsdopenbsdMatch4.0
OR
openbsdopenbsdMatch4.1
OR
openbsdopenbsdMatch4.2
OR
openbsdopenbsdMatch4.3
VendorProductVersionCPE
microsoftinterix6.0cpe:2.3:a:microsoft:interix:6.0:*:10.0.6030.0:*:*:*:*:*
openbsdopenbsd*cpe:2.3:o:openbsd:openbsd:*:*:*:*:*:*:*:*
openbsdopenbsd2.0cpe:2.3:o:openbsd:openbsd:2.0:*:*:*:*:*:*:*
openbsdopenbsd2.1cpe:2.3:o:openbsd:openbsd:2.1:*:*:*:*:*:*:*
openbsdopenbsd2.2cpe:2.3:o:openbsd:openbsd:2.2:*:*:*:*:*:*:*
openbsdopenbsd2.3cpe:2.3:o:openbsd:openbsd:2.3:*:*:*:*:*:*:*
openbsdopenbsd2.4cpe:2.3:o:openbsd:openbsd:2.4:*:*:*:*:*:*:*
openbsdopenbsd2.5cpe:2.3:o:openbsd:openbsd:2.5:*:*:*:*:*:*:*
openbsdopenbsd2.6cpe:2.3:o:openbsd:openbsd:2.6:*:*:*:*:*:*:*
openbsdopenbsd2.7cpe:2.3:o:openbsd:openbsd:2.7:*:*:*:*:*:*:*
Rows per page:
1-10 of 261

CVSS2

4.9

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:N/I:N/A:C

AI Score

6.4

Confidence

Low

EPSS

0.002

Percentile

52.1%