CVE-2009-0537

EUVD-2009-0541
Integer overflow in the fts_build function in fts.c in libc in (1) OpenBSD 4.4 and earlier and (2) Microsoft Interix 6.0 build 10.0.6030.0 allows context-dependent attackers to cause a denial of service (application crash) via a deep directory tree, related to the fts_level structure member, as demonstrated by (a) du, (b) rm, (c) chmod, and (d) chgrp on OpenBSD; and (e) SearchIndexer.exe on Vista Enterprise.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.9 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:N/I:N/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
Affected Products (NVD)
VendorProductVersion
microsoftinterix
6.0
openbsdopenbsd
𝑥
≤ 4.4
openbsdopenbsd
2.0
openbsdopenbsd
2.1
openbsdopenbsd
2.2
openbsdopenbsd
2.3
openbsdopenbsd
2.4
openbsdopenbsd
2.5
openbsdopenbsd
2.6
openbsdopenbsd
2.7
openbsdopenbsd
2.8
openbsdopenbsd
2.9
openbsdopenbsd
3.0
openbsdopenbsd
3.1
openbsdopenbsd
3.2
openbsdopenbsd
3.3
openbsdopenbsd
3.4
openbsdopenbsd
3.5
openbsdopenbsd
3.6
openbsdopenbsd
3.7
openbsdopenbsd
3.8
openbsdopenbsd
3.9
openbsdopenbsd
4.0
openbsdopenbsd
4.1
openbsdopenbsd
4.2
openbsdopenbsd
4.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
glibc
bookworm
2.36-9+deb12u8
fixed
bookworm (security)
2.36-9+deb12u7
fixed
bullseye
2.31-13+deb11u11
fixed
bullseye (security)
2.31-13+deb11u10
fixed
sid
2.40-3
fixed
trixie
2.40-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
glibc
dapper
not-affected
gutsy
not-affected
hardy
not-affected
intrepid
not-affected
Common Weakness Enumeration