CVE Vulnerabilities

CVE-2009-2411

Published: Aug 07, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
8.5 HIGH
AV:N/AC:M/Au:S/C:C/I:C/A:C
RedHat/V2
6.5 IMPORTANT
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V3
Ubuntu
HIGH
root.io logo minimus.io logo echo.ai logo

Multiple integer overflows in the libsvn_delta library in Subversion before 1.5.7, and 1.6.x before 1.6.4, allow remote authenticated users and remote Subversion servers to execute arbitrary code via an svndiff stream with large windows that trigger a heap-based buffer overflow, a related issue to CVE-2009-2412.

Affected Software

NameVendorStart VersionEnd Version
SubversionSubversion*1.5.6 (including)
SubversionSubversion0.22.1 (including)0.22.1 (including)
SubversionSubversion0.23.0 (including)0.23.0 (including)
SubversionSubversion0.24.0 (including)0.24.0 (including)
SubversionSubversion0.24.1 (including)0.24.1 (including)
SubversionSubversion0.24.2 (including)0.24.2 (including)
SubversionSubversion0.25.0 (including)0.25.0 (including)
SubversionSubversion0.27.0 (including)0.27.0 (including)
SubversionSubversion0.28.0 (including)0.28.0 (including)
SubversionSubversion0.28.1 (including)0.28.1 (including)
SubversionSubversion0.28.2 (including)0.28.2 (including)
SubversionSubversion0.29.0 (including)0.29.0 (including)
SubversionSubversion0.30.0 (including)0.30.0 (including)
SubversionSubversion0.31.0 (including)0.31.0 (including)
SubversionSubversion0.32.0 (including)0.32.0 (including)
SubversionSubversion0.32.1 (including)0.32.1 (including)
SubversionSubversion0.33.0 (including)0.33.0 (including)
SubversionSubversion0.33.1 (including)0.33.1 (including)
SubversionSubversion0.34.0 (including)0.34.0 (including)
SubversionSubversion0.35.0 (including)0.35.0 (including)
SubversionSubversion0.35.1 (including)0.35.1 (including)
SubversionSubversion0.36.0 (including)0.36.0 (including)
SubversionSubversion0.37.0 (including)0.37.0 (including)
SubversionSubversion1.0 (including)1.0 (including)
SubversionSubversion1.0.0 (including)1.0.0 (including)
SubversionSubversion1.0.1 (including)1.0.1 (including)
SubversionSubversion1.0.2 (including)1.0.2 (including)
SubversionSubversion1.0.3 (including)1.0.3 (including)
SubversionSubversion1.0.4 (including)1.0.4 (including)
SubversionSubversion1.0.5 (including)1.0.5 (including)
SubversionSubversion1.0.6 (including)1.0.6 (including)
SubversionSubversion1.0.7 (including)1.0.7 (including)
SubversionSubversion1.0.8 (including)1.0.8 (including)
SubversionSubversion1.0.9 (including)1.0.9 (including)
SubversionSubversion1.1.0 (including)1.1.0 (including)
SubversionSubversion1.1.0_rc1 (including)1.1.0_rc1 (including)
SubversionSubversion1.1.0_rc2 (including)1.1.0_rc2 (including)
SubversionSubversion1.1.0_rc3 (including)1.1.0_rc3 (including)
SubversionSubversion1.1.1 (including)1.1.1 (including)
SubversionSubversion1.1.2 (including)1.1.2 (including)
SubversionSubversion1.1.3 (including)1.1.3 (including)
SubversionSubversion1.1.4 (including)1.1.4 (including)
SubversionSubversion1.2.0 (including)1.2.0 (including)
SubversionSubversion1.2.1 (including)1.2.1 (including)
SubversionSubversion1.2.2 (including)1.2.2 (including)
SubversionSubversion1.2.3 (including)1.2.3 (including)
SubversionSubversion1.3.0 (including)1.3.0 (including)
SubversionSubversion1.3.1 (including)1.3.1 (including)
SubversionSubversion1.3.2 (including)1.3.2 (including)
SubversionSubversion1.4.0 (including)1.4.0 (including)
SubversionSubversion1.4.1 (including)1.4.1 (including)
SubversionSubversion1.4.2 (including)1.4.2 (including)
SubversionSubversion1.4.3 (including)1.4.3 (including)
SubversionSubversion1.4.4 (including)1.4.4 (including)
SubversionSubversion1.4.5 (including)1.4.5 (including)
SubversionSubversion1.5.0 (including)1.5.0 (including)
SubversionSubversion1.5.1 (including)1.5.1 (including)
SubversionSubversion1.5.3 (including)1.5.3 (including)
SubversionSubversion1.5.4 (including)1.5.4 (including)
SubversionSubversion1.5.5 (including)1.5.5 (including)
SubversionSubversion1.6.0 (including)1.6.0 (including)
SubversionSubversion1.6.1 (including)1.6.1 (including)
SubversionSubversion1.6.2 (including)1.6.2 (including)
SubversionSubversion1.6.3 (including)1.6.3 (including)
Red Hat Enterprise Linux 4RedHatsubversion-0:1.1.4-3.el4_8.2*
Red Hat Enterprise Linux 5RedHatsubversion-0:1.4.2-4.el5_3.1*
SubversionUbuntudapper*
SubversionUbuntuhardy*
SubversionUbuntuintrepid*
SubversionUbuntujaunty*
SubversionUbuntuupstream*

References