CVE Vulnerabilities

CVE-2009-5024

Published: May 23, 2011 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

ViewVC before 1.1.11 allows remote attackers to bypass the cvsdb row_limit configuration setting, and consequently conduct resource-consumption attacks, via the limit parameter, as demonstrated by a query revision history request.

Affected Software

Name Vendor Start Version End Version
Viewvc Viewvc * 1.1.10 (including)
Viewvc Viewvc 0.8 (including) 0.8 (including)
Viewvc Viewvc 0.9 (including) 0.9 (including)
Viewvc Viewvc 0.9.1 (including) 0.9.1 (including)
Viewvc Viewvc 0.9.2 (including) 0.9.2 (including)
Viewvc Viewvc 0.9.3 (including) 0.9.3 (including)
Viewvc Viewvc 0.9.4 (including) 0.9.4 (including)
Viewvc Viewvc 1.0.0 (including) 1.0.0 (including)
Viewvc Viewvc 1.0.1 (including) 1.0.1 (including)
Viewvc Viewvc 1.0.2 (including) 1.0.2 (including)
Viewvc Viewvc 1.0.3 (including) 1.0.3 (including)
Viewvc Viewvc 1.0.4 (including) 1.0.4 (including)
Viewvc Viewvc 1.0.5 (including) 1.0.5 (including)
Viewvc Viewvc 1.0.6 (including) 1.0.6 (including)
Viewvc Viewvc 1.0.7 (including) 1.0.7 (including)
Viewvc Viewvc 1.0.8 (including) 1.0.8 (including)
Viewvc Viewvc 1.0.9 (including) 1.0.9 (including)
Viewvc Viewvc 1.0.10 (including) 1.0.10 (including)
Viewvc Viewvc 1.0.11 (including) 1.0.11 (including)
Viewvc Viewvc 1.1.0 (including) 1.1.0 (including)
Viewvc Viewvc 1.1.1 (including) 1.1.1 (including)
Viewvc Viewvc 1.1.2 (including) 1.1.2 (including)
Viewvc Viewvc 1.1.3 (including) 1.1.3 (including)
Viewvc Viewvc 1.1.4 (including) 1.1.4 (including)
Viewvc Viewvc 1.1.5 (including) 1.1.5 (including)
Viewvc Viewvc 1.1.6 (including) 1.1.6 (including)
Viewvc Viewvc 1.1.7 (including) 1.1.7 (including)
Viewvc Viewvc 1.1.8 (including) 1.1.8 (including)
Viewvc Viewvc 1.1.9 (including) 1.1.9 (including)

References