CVE-2009-0537
Integer overflow in the fts_build function in fts.c in libc in (1) OpenBSD 4.4 and earlier and (2) Microsoft Interix 6.0 build 10.0.6030.0 allows context-dependent attackers to cause a denial of service (application crash) via a deep directory tree, related to the fts_level structure member, as demonstrated by (a) du, (b) rm, (c) chmod, and (d) chgrp on OpenBSD; and (e) SearchIndexer.exe on Vista Enterprise.
- Affected products
- Interix, Openbsd, Searchindexer.Exe, Vista Enterprise, Chgrp, Chmod, Du, Libc
- Microsoft Interix
- = 6.0
- Openbsd
- ≤ 4.4, 2.0, 2.1, 2.2, 2.3, 2.4, 2.5, 2.6, 2.7, 2.8, 2.9, 3.0, 3.1, 3.2, 3.3, 3.4, 3.5, 3.6, 3.7, 3.8, 3.9, 4.0, 4.1, 4.2, 4.3
- CVSS 2.0
- 4.9 MEDIUM
- EPSS
- 3.6% (89th percentile)
- Weakness
- CWE-189
- NVD status
- Modified
- Published
- 2009-03-09
CVE-2009-0537 at NVD
5 known exploits for CVE-2009-0537
Proof-of-concept code and exploit modules indexed by Sploitus