Lucene search

K
ubuntucveUbuntu.comUB:CVE-2009-0537
HistoryMar 09, 2009 - 12:00 a.m.

CVE-2009-0537

2009-03-0900:00:00
ubuntu.com
ubuntu.com
21

CVSS2

4.9

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:N/I:N/A:C

EPSS

0.002

Percentile

52.1%

Integer overflow in the fts_build function in fts.c in libc in (1) OpenBSD
4.4 and earlier and (2) Microsoft Interix 6.0 build 10.0.6030.0 allows
context-dependent attackers to cause a denial of service (application
crash) via a deep directory tree, related to the fts_level structure
member, as demonstrated by (a) du, (b) rm, © chmod, and (d) chgrp on
OpenBSD; and (e) SearchIndexer.exe on Vista Enterprise.

Notes

Author Note
jdstrand per kees, Ubuntu is not affected

CVSS2

4.9

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:N/I:N/A:C

EPSS

0.002

Percentile

52.1%