Multiple integer overflows in the libsvn_delta library in Subversion before 1.5.7, and 1.6.x before 1.6.4, allow remote authenticated users and remote Subversion servers to execute arbitrary code via an svndiff stream with large windows that trigger a heap-based buffer overflow, a related issue to CVE-2009-2412.
2009-08-07T19:30:00.297
2025-04-09T00:30:58.490
Deferred
CVSSv2: 8.5 (HIGH)
AV:N/AC:M/Au:S/C:C/I:C/A:C
6.8
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | subversion | subversion | ≤ 1.5.6 | Yes |
Application | subversion | subversion | 0.22.1 | Yes |
Application | subversion | subversion | 0.23.0 | Yes |
Application | subversion | subversion | 0.24.0 | Yes |
Application | subversion | subversion | 0.24.1 | Yes |
Application | subversion | subversion | 0.24.2 | Yes |
Application | subversion | subversion | 0.25.0 | Yes |
Application | subversion | subversion | 0.27.0 | Yes |
Application | subversion | subversion | 0.28.0 | Yes |
Application | subversion | subversion | 0.28.1 | Yes |
Application | subversion | subversion | 0.28.2 | Yes |
Application | subversion | subversion | 0.29.0 | Yes |
Application | subversion | subversion | 0.30.0 | Yes |
Application | subversion | subversion | 0.31.0 | Yes |
Application | subversion | subversion | 0.32.0 | Yes |
Application | subversion | subversion | 0.32.1 | Yes |
Application | subversion | subversion | 0.33.0 | Yes |
Application | subversion | subversion | 0.33.1 | Yes |
Application | subversion | subversion | 0.34.0 | Yes |
Application | subversion | subversion | 0.35.0 | Yes |
Application | subversion | subversion | 0.35.1 | Yes |
Application | subversion | subversion | 0.36.0 | Yes |
Application | subversion | subversion | 0.37.0 | Yes |
Application | subversion | subversion | 1.0 | Yes |
Application | subversion | subversion | 1.0.0 | Yes |
Application | subversion | subversion | 1.0.1 | Yes |
Application | subversion | subversion | 1.0.2 | Yes |
Application | subversion | subversion | 1.0.3 | Yes |
Application | subversion | subversion | 1.0.4 | Yes |
Application | subversion | subversion | 1.0.5 | Yes |
Application | subversion | subversion | 1.0.6 | Yes |
Application | subversion | subversion | 1.0.7 | Yes |
Application | subversion | subversion | 1.0.8 | Yes |
Application | subversion | subversion | 1.0.9 | Yes |
Application | subversion | subversion | 1.1.0 | Yes |
Application | subversion | subversion | 1.1.0_rc1 | Yes |
Application | subversion | subversion | 1.1.0_rc2 | Yes |
Application | subversion | subversion | 1.1.0_rc3 | Yes |
Application | subversion | subversion | 1.1.1 | Yes |
Application | subversion | subversion | 1.1.2 | Yes |
Application | subversion | subversion | 1.1.3 | Yes |
Application | subversion | subversion | 1.1.4 | Yes |
Application | subversion | subversion | 1.2.0 | Yes |
Application | subversion | subversion | 1.2.1 | Yes |
Application | subversion | subversion | 1.2.2 | Yes |
Application | subversion | subversion | 1.2.3 | Yes |
Application | subversion | subversion | 1.3.0 | Yes |
Application | subversion | subversion | 1.3.1 | Yes |
Application | subversion | subversion | 1.3.2 | Yes |
Application | subversion | subversion | 1.4.0 | Yes |
Application | subversion | subversion | 1.4.1 | Yes |
Application | subversion | subversion | 1.4.2 | Yes |
Application | subversion | subversion | 1.4.3 | Yes |
Application | subversion | subversion | 1.4.4 | Yes |
Application | subversion | subversion | 1.4.5 | Yes |
Application | subversion | subversion | 1.5.0 | Yes |
Application | subversion | subversion | 1.5.1 | Yes |
Application | subversion | subversion | 1.5.3 | Yes |
Application | subversion | subversion | 1.5.4 | Yes |
Application | subversion | subversion | 1.5.5 | Yes |
Application | subversion | subversion | 1.6.0 | Yes |
Application | subversion | subversion | 1.6.1 | Yes |
Application | subversion | subversion | 1.6.2 | Yes |
Application | subversion | subversion | 1.6.3 | Yes |