CVE-2009-2411: Buffer Overflow
Multiple integer overflows in the libsvndelta library in Subversion before 1.5.7, and 1.6.x before 1.6.4, allow remote authenticated users and remote Subversion servers to execute arbitrary code via an svndiff stream with large windows that trigger a heap-based buffer overflow, a related issue to CVE-2009-2412.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2411?
CVE-2009-2411 is classified as a critical vulnerability that can lead to remote code execution.
How do I fix CVE-2009-2411?
To fix CVE-2009-2411, upgrade Subversion to version 1.5.7 or later, or 1.6.4 or later.
What type of vulnerability is CVE-2009-2411?
CVE-2009-2411 is an integer overflow vulnerability in the libsvn_delta library.
What versions of Subversion are affected by CVE-2009-2411?
CVE-2009-2411 affects Subversion versions prior to 1.5.7 and 1.6.x before 1.6.4.
Can CVE-2009-2411 be exploited remotely?
Yes, CVE-2009-2411 can be exploited by remote authenticated users via specially crafted svndiff streams.