4.9

CVE-2009-0537

Exploit

Integer overflow in the fts_build function in fts.c in libc in (1) OpenBSD 4.4 and earlier and (2) Microsoft Interix 6.0 build 10.0.6030.0 allows context-dependent attackers to cause a denial of service (application crash) via a deep directory tree, related to the fts_level structure member, as demonstrated by (a) du, (b) rm, (c) chmod, and (d) chgrp on OpenBSD; and (e) SearchIndexer.exe on Vista Enterprise.

Data is provided by the National Vulnerability Database (NVD)
MicrosoftInterix Version6.0 Edition10.0.6030.0
OpenbsdOpenbsd Version <= 4.4
OpenbsdOpenbsd Version2.0
OpenbsdOpenbsd Version2.1
OpenbsdOpenbsd Version2.2
OpenbsdOpenbsd Version2.3
OpenbsdOpenbsd Version2.4
OpenbsdOpenbsd Version2.5
OpenbsdOpenbsd Version2.6
OpenbsdOpenbsd Version2.7
OpenbsdOpenbsd Version2.8
OpenbsdOpenbsd Version2.9
OpenbsdOpenbsd Version3.0
OpenbsdOpenbsd Version3.1
OpenbsdOpenbsd Version3.2
OpenbsdOpenbsd Version3.3
OpenbsdOpenbsd Version3.4
OpenbsdOpenbsd Version3.5
OpenbsdOpenbsd Version3.6
OpenbsdOpenbsd Version3.7
OpenbsdOpenbsd Version3.8
OpenbsdOpenbsd Version3.9
OpenbsdOpenbsd Version4.0
OpenbsdOpenbsd Version4.1
OpenbsdOpenbsd Version4.2
OpenbsdOpenbsd Version4.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 3.66% 0.874
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.9 3.9 6.9
AV:L/AC:L/Au:N/C:N/I:N/A:C