← Vulnerability feed

Vulnerability record · CVE-2009-2411 · published 7 August 2009

CVE-2009-2411: Subversion vulnerability

Subversion · Subversion

Multiple integer overflows in the libsvn_delta library in Subversion before 1.5.7, and 1.6.x before 1.6.4, allow remote authenticated users and remote Subversion servers to execute arbitrary code via an svndiff stream with large windows that trigger a heap-based buffer overflow, a related issue to CVE-2009-2412.

8.5 CVSS 2.0 High EPSS 5.1% · top 7.9% CWE-189 · CWE-189
8.5CVSS 2.0 base score
5.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
52References
16 Jun 2026Last modified by NVD

Description

Multiple integer overflows in the libsvn_delta library in Subversion before 1.5.7, and 1.6.x before 1.6.4, allow remote authenticated users and remote Subversion servers to execute arbitrary code via an svndiff stream with large windows that trigger a heap-based buffer overflow, a related issue to CVE-2009-2412.

AV:N/AC:M/Au:S/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://archives.neohapsis.com/archives/bugtraq/2009-08/0056.html
http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html
http://osvdb.org/56856
http://secunia.com/advisories/36184 Vendor Advisory
http://secunia.com/advisories/36224
http://secunia.com/advisories/36232
http://secunia.com/advisories/36257
http://secunia.com/advisories/36262
http://subversion.tigris.org/security/CVE-2009-2411-advisory.txt
http://support.apple.com/kb/HT3937
http://svn.collab.net/repos/svn/tags/1.5.7/CHANGES
http://svn.collab.net/repos/svn/tags/1.6.4/CHANGES
http://svn.haxx.se/dev/archive-2009-08/0107.shtml
http://svn.haxx.se/dev/archive-2009-08/0108.shtml
http://svn.haxx.se/dev/archive-2009-08/0110.shtml
http://www.debian.org/security/2009/dsa-1855
http://www.mandriva.com/security/advisories?name=MDVSA-2009:199
http://www.redhat.com/support/errata/RHSA-2009-1203.html
http://www.securityfocus.com/bid/35983
http://www.securitytracker.com/id?1022697
http://www.ubuntu.com/usn/usn-812-1
http://www.vupen.com/english/advisories/2009/2180 Vendor Advisory
http://www.vupen.com/english/advisories/2009/3184
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11465
https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00469.html
https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00485.html
http://archives.neohapsis.com/archives/bugtraq/2009-08/0056.html
http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html
http://osvdb.org/56856
http://secunia.com/advisories/36184 Vendor Advisory
http://secunia.com/advisories/36224
http://secunia.com/advisories/36232
http://secunia.com/advisories/36257
http://secunia.com/advisories/36262
http://subversion.tigris.org/security/CVE-2009-2411-advisory.txt
http://support.apple.com/kb/HT3937
http://svn.collab.net/repos/svn/tags/1.5.7/CHANGES
http://svn.collab.net/repos/svn/tags/1.6.4/CHANGES
http://svn.haxx.se/dev/archive-2009-08/0107.shtml
http://svn.haxx.se/dev/archive-2009-08/0108.shtml

Track CVE-2009-2411 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2004-0413Openpkg vulnerabilitylibsvn_ra_svn in Subversion 1.0.4 trusts the length field of (1) svn://, (2) svn+ssh://, and (3) other svn protocol URL strings, which allows remote …EPSS 5.9%7.5CVE-2004-0397Subversion apr_time_t conversion stack buffer overflowSubversion 1.0.2 and earlier contains a stack-based buffer overflow in the apr_time_t data conversion routine. A remote attacker can trigger it throu…EPSS 75%analysed6.0CVE-2007-3846Subversion path traversal vulnerabilityDirectory traversal vulnerability in Subversion before 1.4.5, as used by TortoiseSVN before 1.4.5 and possibly other products, when run on Windows-ba…EPSS 1.6%5.0CVE-2004-0749Subversion vulnerabilityThe mod_authz_svn module in Subversion 1.0.7 and earlier does not properly restrict access to all metadata on unreadable paths, which could allow rem…EPSS 1.5%2.1CVE-2007-2448Subversion vulnerabilitySubversion 1.4.3 and earlier does not properly implement the "partial access" privilege for users who have access to changed paths but not copied pat…EPSS 1.5%2.1CVE-2004-1438Subversion vulnerabilityThe mod_authz_svn Apache module for Subversion 1.0.4-r1 and earlier allows remote authenticated users, with write access to the repository, to read u…EPSS 0.70%8.4CVE-2013-2094Linux Kernel perf_swevent_init Integer Type Flaw Enables Local Privilege EscalationThe perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, allowing a local user to…KEVEPSS 48%analysed

Source: NIST National Vulnerability Database (record CVE-2009-2411), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.