Lucene search

K
ubuntucveUbuntu.comUB:CVE-2009-2411
HistoryAug 07, 2009 - 12:00 a.m.

CVE-2009-2411

2009-08-0700:00:00
ubuntu.com
ubuntu.com
19

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

0.11 Low

EPSS

Percentile

95.2%

Multiple integer overflows in the libsvn_delta library in Subversion before
1.5.7, and 1.6.x before 1.6.4, allow remote authenticated users and remote
Subversion servers to execute arbitrary code via an svndiff stream with
large windows that trigger a heap-based buffer overflow, a related issue to
CVE-2009-2412.

OSVersionArchitecturePackageVersionFilename
ubuntu6.06noarchsubversion< 1.3.1-3ubuntu1.2UNKNOWN
ubuntu8.04noarchsubversion< 1.4.6dfsg1-2ubuntu1.1UNKNOWN
ubuntu8.10noarchsubversion< 1.5.1dfsg1-1ubuntu2.1UNKNOWN
ubuntu9.04noarchsubversion< 1.5.4dfsg1-1ubuntu2.1UNKNOWN

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

0.11 Low

EPSS

Percentile

95.2%