4.9

CVE-2009-0537

Exploit

Integer overflow in the fts_build function in fts.c in libc in (1) OpenBSD 4.4 and earlier and (2) Microsoft Interix 6.0 build 10.0.6030.0 allows context-dependent attackers to cause a denial of service (application crash) via a deep directory tree, related to the fts_level structure member, as demonstrated by (a) du, (b) rm, (c) chmod, and (d) chgrp on OpenBSD; and (e) SearchIndexer.exe on Vista Enterprise.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MicrosoftInterix Version6.0 Edition10.0.6030.0
OpenbsdOpenbsd Version <= 4.4
OpenbsdOpenbsd Version2.0
OpenbsdOpenbsd Version2.1
OpenbsdOpenbsd Version2.2
OpenbsdOpenbsd Version2.3
OpenbsdOpenbsd Version2.4
OpenbsdOpenbsd Version2.5
OpenbsdOpenbsd Version2.6
OpenbsdOpenbsd Version2.7
OpenbsdOpenbsd Version2.8
OpenbsdOpenbsd Version2.9
OpenbsdOpenbsd Version3.0
OpenbsdOpenbsd Version3.1
OpenbsdOpenbsd Version3.2
OpenbsdOpenbsd Version3.3
OpenbsdOpenbsd Version3.4
OpenbsdOpenbsd Version3.5
OpenbsdOpenbsd Version3.6
OpenbsdOpenbsd Version3.7
OpenbsdOpenbsd Version3.8
OpenbsdOpenbsd Version3.9
OpenbsdOpenbsd Version4.0
OpenbsdOpenbsd Version4.1
OpenbsdOpenbsd Version4.2
OpenbsdOpenbsd Version4.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.66% 0.874
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.9 3.9 6.9
AV:L/AC:L/Au:N/C:N/I:N/A:C