HIGH
subversion: multiple heap overflow issues
Published Aug 7, 2009
8.5
HIGHCVSS 2.0
EPSS 5.11%
Description
Multiple integer overflows in the libsvn_delta library in Subversion before 1.5.7, and 1.6.x before 1.6.4, allow remote authenticated users and remote Subversion servers to execute arbitrary code via an svndiff stream with large windows that trigger a heap-based buffer overflow, a related issue to CVE-2009-2412.
Affected products
No data.
OR
- ≤ 1.5.6
- 0.22.1
- 0.23.0
- 0.24.0
- 0.24.1
- 0.24.2
- 0.25.0
- 0.27.0
- 0.28.0
- 0.28.1
- 0.28.2
- 0.29.0
- 0.30.0
- 0.31.0
- 0.32.0
- 0.32.1
- 0.33.0
- 0.33.1
- 0.34.0
- 0.35.0
- 0.35.1
- 0.36.0
- 0.37.0
- 1.0
- 1.0.0
- 1.0.1
- 1.0.2
- 1.0.3
- 1.0.4
- 1.0.5
- 1.0.6
- 1.0.7
- 1.0.8
- 1.0.9
- 1.1.0
- 1.1.0_rc1
- 1.1.0_rc2
- 1.1.0_rc3
- 1.1.1
- 1.1.2
- 1.1.3
- 1.1.4
- 1.2.0
- 1.2.1
- 1.2.2
- 1.2.3
- 1.3.0
- 1.3.1
- 1.3.2
- 1.4.0
- 1.4.1
- 1.4.2
- 1.4.3
- 1.4.4
- 1.4.5
- 1.5.0
- 1.5.1
- 1.5.3
- 1.5.4
- 1.5.5
- 1.6.0
- 1.6.1
- 1.6.2
- 1.6.3
No data.
Red Hat Enterprise Linux 4
subversion-0:1.1.4-3.el4_8.2
Fixed · RHSA-2009:1203
Red Hat Enterprise Linux 5
subversion-0:1.4.2-4.el5_3.1
Fixed · RHSA-2009:1203
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 4 | subversion-0:1.1.4-3.el4_8.2 | Fixed | RHSA-2009:1203 |
| Red Hat Enterprise Linux 5 | subversion-0:1.4.2-4.el5_3.1 | Fixed | RHSA-2009:1203 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (30)
- http://archives.neohapsis.com/archives/bugtraq/2009-08/0056.html mailing-listx_refsource_BUGTRAQ
- http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html vendor-advisoryx_refsource_APPLE
- http://osvdb.org/56856 vdb-entryx_refsource_OSVDB
- http://secunia.com/advisories/36184 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/36224 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/36232 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/36257 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/36262 third-party-advisoryx_refsource_SECUNIA
- http://subversion.tigris.org/security/CVE-2009-2411-advisory.txt x_refsource_CONFIRM
- http://support.apple.com/kb/HT3937 x_refsource_CONFIRM
- http://svn.collab.net/repos/svn/tags/1.5.7/CHANGES x_refsource_CONFIRM
- http://svn.collab.net/repos/svn/tags/1.6.4/CHANGES x_refsource_CONFIRM
- http://svn.haxx.se/dev/archive-2009-08/0107.shtml mailing-listx_refsource_MLIST
- http://svn.haxx.se/dev/archive-2009-08/0108.shtml mailing-listx_refsource_MLIST
- http://svn.haxx.se/dev/archive-2009-08/0110.shtml mailing-listx_refsource_MLIST
- http://www.debian.org/security/2009/dsa-1855 vendor-advisoryx_refsource_DEBIAN
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:199 vendor-advisoryx_refsource_MANDRIVA
- http://www.redhat.com/support/errata/RHSA-2009-1203.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/bid/35983 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id?1022697 vdb-entryx_refsource_SECTRACK
- http://www.ubuntu.com/usn/usn-812-1 vendor-advisoryx_refsource_UBUNTU
- http://www.vupen.com/english/advisories/2009/2180 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2009/3184 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2009-2411 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=514744 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2009-2411
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11465 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2009-2411
- https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00469.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00485.html vendor-advisoryx_refsource_FEDORA
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 7, 2009
Updated Aug 7, 2024
Reserved Jul 9, 2009
Link CVE-2009-2411
CISA Vulnrichment
Updated n/a