gsd-2009-0148
Vulnerability from gsd
Modified
2023-12-13 01:19
Details
Multiple buffer overflows in Cscope before 15.7a allow remote attackers to execute arbitrary code via long strings in input such as (1) source-code tokens and (2) pathnames, related to integer overflows in some cases. NOTE: this issue exists because of an incomplete fix for CVE-2004-2541.
Aliases
Aliases
{ "GSD": { "alias": "CVE-2009-0148", "description": "Multiple buffer overflows in Cscope before 15.7a allow remote attackers to execute arbitrary code via long strings in input such as (1) source-code tokens and (2) pathnames, related to integer overflows in some cases. NOTE: this issue exists because of an incomplete fix for CVE-2004-2541.", "id": "GSD-2009-0148", "references": [ "https://www.suse.com/security/cve/CVE-2009-0148.html", "https://www.debian.org/security/2009/dsa-1806", "https://access.redhat.com/errata/RHSA-2009:1102", "https://access.redhat.com/errata/RHSA-2009:1101", "https://linux.oracle.com/cve/CVE-2009-0148.html" ] }, "gsd": { "metadata": { "exploitCode": "unknown", "remediation": "unknown", "reportConfidence": "confirmed", "type": "vulnerability" }, "osvSchema": { "aliases": [ "CVE-2009-0148" ], "details": "Multiple buffer overflows in Cscope before 15.7a allow remote attackers to execute arbitrary code via long strings in input such as (1) source-code tokens and (2) pathnames, related to integer overflows in some cases. NOTE: this issue exists because of an incomplete fix for CVE-2004-2541.", "id": "GSD-2009-0148", "modified": "2023-12-13T01:19:44.317109Z", "schema_version": "1.4.0" } }, "namespaces": { "cve.org": { "CVE_data_meta": { "ASSIGNER": "cve@mitre.org", "ID": "CVE-2009-0148", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "n/a", "version": { "version_data": [ { "version_value": "n/a" } ] } } ] }, "vendor_name": "n/a" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "Multiple buffer overflows in Cscope before 15.7a allow remote attackers to execute arbitrary code via long strings in input such as (1) source-code tokens and (2) pathnames, related to integer overflows in some cases. NOTE: this issue exists because of an incomplete fix for CVE-2004-2541." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "n/a" } ] } ] }, "references": { "reference_data": [ { "name": "[oss-security] 20090506 Re: Old cscope buffer overflow", "refsource": "MLIST", "url": "http://www.openwall.com/lists/oss-security/2009/05/06/9" }, { "name": "35462", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/35462" }, { "name": "http://support.apple.com/kb/HT3549", "refsource": "CONFIRM", "url": "http://support.apple.com/kb/HT3549" }, { "name": "RHSA-2009:1101", "refsource": "REDHAT", "url": "http://www.redhat.com/support/errata/RHSA-2009-1101.html" }, { "name": "[cscope-cvs] 20090410 CVS: cscope/src snprintf.c, NONE, 1.1 build.c, 1.14, 1.15 command.c, 1.32, 1.33 dir.c, 1.30, 1.31 display.c, 1.29, 1.30 edit.c, 1.6, 1.7 exec.c, 1.11, 1.12 find.c, 1.20, 1.21 global.h, 1.36, 1.37 main.c, 1.45, 1.46 Makefile.am, 1.12, 1.13 Makefile.in, 1.15, 1.16 vpaccess.c, 1.2, 1.3 vpfopen.c, 1.3, 1.4 vpopen.c, 1.4, 1.5", "refsource": "MLIST", "url": "http://sourceforge.net/mailarchive/forum.php?thread_name=E1LsGx3-00015K-TN%40ddv4jf1.ch3.sourceforge.com\u0026forum_name=cscope-cvs" }, { "name": "35074", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/35074" }, { "name": "APPLE-SA-2009-05-12", "refsource": "APPLE", "url": "http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" }, { "name": "ADV-2009-1238", "refsource": "VUPEN", "url": "http://www.vupen.com/english/advisories/2009/1238" }, { "name": "35214", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/35214" }, { "name": "RHSA-2009:1102", "refsource": "REDHAT", "url": "http://www.redhat.com/support/errata/RHSA-2009-1102.html" }, { "name": "GLSA-200905-02", "refsource": "GENTOO", "url": "http://security.gentoo.org/glsa/glsa-200905-02.xml" }, { "name": "TA09-133A", "refsource": "CERT", "url": "http://www.us-cert.gov/cas/techalerts/TA09-133A.html" }, { "name": "35213", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/35213" }, { "name": "ADV-2009-1297", "refsource": "VUPEN", "url": "http://www.vupen.com/english/advisories/2009/1297" }, { "name": "34805", "refsource": "BID", "url": "http://www.securityfocus.com/bid/34805" }, { "name": "http://sourceforge.net/forum/forum.php?forum_id=947983", "refsource": "CONFIRM", "url": "http://sourceforge.net/forum/forum.php?forum_id=947983" }, { "name": "1022218", "refsource": "SECTRACK", "url": "http://www.securitytracker.com/id?1022218" }, { "name": "DSA-1806", "refsource": "DEBIAN", "url": "http://www.debian.org/security/2009/dsa-1806" }, { "name": "oval:org.mitre.oval:def:9633", "refsource": "OVAL", "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9633" }, { "name": "34978", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/34978" }, { "name": "http://sourceforge.net/project/shownotes.php?group_id=4664\u0026release_id=679527", "refsource": "CONFIRM", "url": "http://sourceforge.net/project/shownotes.php?group_id=4664\u0026release_id=679527" }, { "name": "https://bugzilla.redhat.com/show_bug.cgi?id=490667", "refsource": "CONFIRM", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=490667" } ] } }, "nvd.nist.gov": { "configurations": { "CVE_data_version": "4.0", "nodes": [ { "children": [], "cpe_match": [ { "cpe23Uri": "cpe:2.3:a:cscope:cscope:15.5:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true }, { "cpe23Uri": "cpe:2.3:a:cscope:cscope:15.6:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true }, { "cpe23Uri": "cpe:2.3:a:cscope:cscope:15.4:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true }, { "cpe23Uri": "cpe:2.3:a:cscope:cscope:15.7:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true }, { "cpe23Uri": "cpe:2.3:a:cscope:cscope:13.0:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true }, { "cpe23Uri": "cpe:2.3:a:cscope:cscope:15.1:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true }, { "cpe23Uri": "cpe:2.3:a:cscope:cscope:15.0bl2:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true }, { "cpe23Uri": "cpe:2.3:a:cscope:cscope:15.3:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true } ], "operator": "OR" } ] }, "cve": { "CVE_data_meta": { "ASSIGNER": "cve@mitre.org", "ID": "CVE-2009-0148" }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "en", "value": "Multiple buffer overflows in Cscope before 15.7a allow remote attackers to execute arbitrary code via long strings in input such as (1) source-code tokens and (2) pathnames, related to integer overflows in some cases. NOTE: this issue exists because of an incomplete fix for CVE-2004-2541." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "en", "value": "CWE-119" } ] } ] }, "references": { "reference_data": [ { "name": "ADV-2009-1238", "refsource": "VUPEN", "tags": [ "Vendor Advisory" ], "url": "http://www.vupen.com/english/advisories/2009/1238" }, { "name": "[cscope-cvs] 20090410 CVS: cscope/src snprintf.c, NONE, 1.1 build.c, 1.14, 1.15 command.c, 1.32, 1.33 dir.c, 1.30, 1.31 display.c, 1.29, 1.30 edit.c, 1.6, 1.7 exec.c, 1.11, 1.12 find.c, 1.20, 1.21 global.h, 1.36, 1.37 main.c, 1.45, 1.46 Makefile.am, 1.12, 1.13 Makefile.in, 1.15, 1.16 vpaccess.c, 1.2, 1.3 vpfopen.c, 1.3, 1.4 vpopen.c, 1.4, 1.5", "refsource": "MLIST", "tags": [], "url": "http://sourceforge.net/mailarchive/forum.php?thread_name=E1LsGx3-00015K-TN%40ddv4jf1.ch3.sourceforge.com\u0026forum_name=cscope-cvs" }, { "name": "https://bugzilla.redhat.com/show_bug.cgi?id=490667", "refsource": "CONFIRM", "tags": [], "url": "https://bugzilla.redhat.com/show_bug.cgi?id=490667" }, { "name": "http://sourceforge.net/project/shownotes.php?group_id=4664\u0026release_id=679527", "refsource": "CONFIRM", "tags": [ "Patch" ], "url": "http://sourceforge.net/project/shownotes.php?group_id=4664\u0026release_id=679527" }, { "name": "http://sourceforge.net/forum/forum.php?forum_id=947983", "refsource": "CONFIRM", "tags": [ "Patch" ], "url": "http://sourceforge.net/forum/forum.php?forum_id=947983" }, { "name": "34978", "refsource": "SECUNIA", "tags": [ "Vendor Advisory" ], "url": "http://secunia.com/advisories/34978" }, { "name": "[oss-security] 20090506 Re: Old cscope buffer overflow", "refsource": "MLIST", "tags": [], "url": "http://www.openwall.com/lists/oss-security/2009/05/06/9" }, { "name": "35074", "refsource": "SECUNIA", "tags": [ "Vendor Advisory" ], "url": "http://secunia.com/advisories/35074" }, { "name": "http://support.apple.com/kb/HT3549", "refsource": "CONFIRM", "tags": [], "url": "http://support.apple.com/kb/HT3549" }, { "name": "APPLE-SA-2009-05-12", "refsource": "APPLE", "tags": [], "url": "http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" }, { "name": "1022218", "refsource": "SECTRACK", "tags": [], "url": "http://www.securitytracker.com/id?1022218" }, { "name": "TA09-133A", "refsource": "CERT", "tags": [ "US Government Resource" ], "url": "http://www.us-cert.gov/cas/techalerts/TA09-133A.html" }, { "name": "ADV-2009-1297", "refsource": "VUPEN", "tags": [ "Vendor Advisory" ], "url": "http://www.vupen.com/english/advisories/2009/1297" }, { "name": "35214", "refsource": "SECUNIA", "tags": [ "Vendor Advisory" ], "url": "http://secunia.com/advisories/35214" }, { "name": "DSA-1806", "refsource": "DEBIAN", "tags": [], "url": "http://www.debian.org/security/2009/dsa-1806" }, { "name": "GLSA-200905-02", "refsource": "GENTOO", "tags": [], "url": "http://security.gentoo.org/glsa/glsa-200905-02.xml" }, { "name": "35213", "refsource": "SECUNIA", "tags": [ "Vendor Advisory" ], "url": "http://secunia.com/advisories/35213" }, { "name": "RHSA-2009:1101", "refsource": "REDHAT", "tags": [], "url": "http://www.redhat.com/support/errata/RHSA-2009-1101.html" }, { "name": "RHSA-2009:1102", "refsource": "REDHAT", "tags": [], "url": "http://www.redhat.com/support/errata/RHSA-2009-1102.html" }, { "name": "34805", "refsource": "BID", "tags": [], "url": "http://www.securityfocus.com/bid/34805" }, { "name": "35462", "refsource": "SECUNIA", "tags": [ "Vendor Advisory" ], "url": "http://secunia.com/advisories/35462" }, { "name": "oval:org.mitre.oval:def:9633", "refsource": "OVAL", "tags": [], "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9633" } ] } }, "impact": { "baseMetricV2": { "cvssV2": { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "COMPLETE", "baseScore": 9.3, "confidentialityImpact": "COMPLETE", "integrityImpact": "COMPLETE", "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C", "version": "2.0" }, "exploitabilityScore": 8.6, "impactScore": 10.0, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "severity": "HIGH", "userInteractionRequired": true } }, "lastModifiedDate": "2017-09-29T01:33Z", "publishedDate": "2009-05-05T17:30Z" } } }
Loading…
Loading…
Sightings
Author | Source | Type | Date |
---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…