ViewVC 'cvsdb.py' Remote Denial of Service Vulnerability
BID:47928
Info
ViewVC 'cvsdb.py' Remote Denial of Service Vulnerability
| Bugtraq ID: | 47928 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2009-5024 |
| Remote: | Yes |
| Local: | No |
| Published: | May 19 2011 12:00AM |
| Updated: | Apr 16 2015 05:42PM |
| Credit: | David Carson |
| Vulnerable: |
ViewVC ViewVC 1.1.5 ViewVC ViewVC 1.1.4 ViewVC ViewVC 1.1.3 ViewVC ViewVC 1.1.2 ViewVC ViewVC 1.0.11 ViewVC ViewVC 1.0.10 ViewVC ViewVC 1.0.9 ViewVC ViewVC 1.0.8 ViewVC ViewVC 1.0.5 ViewVC ViewVC 1.0.3 ViewVC ViewVC 1.0.2 ViewVC ViewVC 1.1.10 SuSE openSUSE 11.4 SuSE openSUSE 11.3 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: |
ViewVC ViewVC 1.1.11 |
Discussion
ViewVC 'cvsdb.py' Remote Denial of Service Vulnerability
ViewVC is prone to a remote denial-of-service vulnerability.
Attackers can exploit this issue to cause the server to consume excessive resources, denying service to legitimate users.
Versions prior to ViewVC 1.1.11 are vulnerable.
ViewVC is prone to a remote denial-of-service vulnerability.
Attackers can exploit this issue to cause the server to consume excessive resources, denying service to legitimate users.
Versions prior to ViewVC 1.1.11 are vulnerable.
Exploit / POC
ViewVC 'cvsdb.py' Remote Denial of Service Vulnerability
Attackers can exploit this issue using a browser.
Attackers can exploit this issue using a browser.
Solution / Fix
ViewVC 'cvsdb.py' Remote Denial of Service Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
ViewVC 'cvsdb.py' Remote Denial of Service Vulnerability
References:
References:
- Issue 433 ViewVC fails to warn about incomplete query results (ViewVC)
- ViewVC Homepage (ViewVC)