[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

252271

 
 

909

 
 

196835

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SA:2009:044 -- SUSE subversion remote code execution

ID: oval:org.secpod.oval:def:400090Date: (C)2012-01-31   (M)2021-06-02
Class: PATCHFamily: unix




Subversion is a revision control system, which is mainly used for code development. The ibsvn_delta library is vulnerable to integer overflows while processing svndiff streams, this leads to overflows on the heap because of insufficient memory allocation. This bug can be exploited by clients with commit access to cause a remote denial-of-service or arbitrary code execution. It can also be exploited in the other direction from a server to a client that tries to do a checkout or update.

Platform:
openSUSE 10.3
openSUSE 11.1
openSUSE 11.0
Product:
subversion
Reference:
SUSE-SA:2009:044
CVE-2009-2411
CVE-2009-2666
CVE    2
CVE-2009-2411
CVE-2009-2666
CPE    3
cpe:/o:opensuse:opensuse:11.1
cpe:/o:opensuse:opensuse:11.0
cpe:/o:opensuse:opensuse:10.3

© SecPod Technologies