CVE Vulnerabilities

CVE-2009-0537

Published: Mar 09, 2009 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.9 MEDIUM
AV:L/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
RedHat/V3
Ubuntu

Integer overflow in the fts_build function in fts.c in libc in (1) OpenBSD 4.4 and earlier and (2) Microsoft Interix 6.0 build 10.0.6030.0 allows context-dependent attackers to cause a denial of service (application crash) via a deep directory tree, related to the fts_level structure member, as demonstrated by (a) du, (b) rm, (c) chmod, and (d) chgrp on OpenBSD; and (e) SearchIndexer.exe on Vista Enterprise.

Affected Software

Name Vendor Start Version End Version
Interix Microsoft 6.0 (including) 6.0 (including)
Openbsd Openbsd * 4.4 (including)
Openbsd Openbsd 2.0 (including) 2.0 (including)
Openbsd Openbsd 2.1 (including) 2.1 (including)
Openbsd Openbsd 2.2 (including) 2.2 (including)
Openbsd Openbsd 2.3 (including) 2.3 (including)
Openbsd Openbsd 2.4 (including) 2.4 (including)
Openbsd Openbsd 2.5 (including) 2.5 (including)
Openbsd Openbsd 2.6 (including) 2.6 (including)
Openbsd Openbsd 2.7 (including) 2.7 (including)
Openbsd Openbsd 2.8 (including) 2.8 (including)
Openbsd Openbsd 2.9 (including) 2.9 (including)
Openbsd Openbsd 3.0 (including) 3.0 (including)
Openbsd Openbsd 3.1 (including) 3.1 (including)
Openbsd Openbsd 3.2 (including) 3.2 (including)
Openbsd Openbsd 3.3 (including) 3.3 (including)
Openbsd Openbsd 3.4 (including) 3.4 (including)
Openbsd Openbsd 3.5 (including) 3.5 (including)
Openbsd Openbsd 3.6 (including) 3.6 (including)
Openbsd Openbsd 3.7 (including) 3.7 (including)
Openbsd Openbsd 3.8 (including) 3.8 (including)
Openbsd Openbsd 3.9 (including) 3.9 (including)
Openbsd Openbsd 4.0 (including) 4.0 (including)
Openbsd Openbsd 4.1 (including) 4.1 (including)
Openbsd Openbsd 4.2 (including) 4.2 (including)
Openbsd Openbsd 4.3 (including) 4.3 (including)

References