CVE-2009-5024: Medium severity viewvc vulnerability
ViewVC before 1.1.11 allows remote attackers to bypass the cvsdb rowlimit configuration setting, and consequently conduct resource-consumption attacks, via the limit parameter, as demonstrated by a "query revision history" request.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2009-5024?
CVE-2009-5024 is classified as a medium severity vulnerability due to its potential for resource consumption attacks.
How do I fix CVE-2009-5024?
To fix CVE-2009-5024, upgrade ViewVC to version 1.1.11 or later, which resolves this issue.
What systems are affected by CVE-2009-5024?
CVE-2009-5024 affects ViewVC versions 0.8 through 1.1.10.
What type of attack can CVE-2009-5024 enable?
CVE-2009-5024 can enable remote attackers to conduct resource-consumption attacks by bypassing the cvsdb row_limit configuration.
What does the limit parameter in CVE-2009-5024 do?
In the context of CVE-2009-5024, the limit parameter allows attackers to manipulate query revision history requests, leading to potential abuse.