CVE-2009-5024 Information
Feb 14, 2021
cve
Description
ViewVC before 1.1.11 allows remote attackers to bypass the cvsdb row_limit configuration setting and consequently conduct resource-consumption attacks via the limit parameter as demonstrated by a \query revision history\ request.
Reference
http://openwall.com/lists/oss-security/2011/05/19/1 http://openwall.com/lists/oss-security/2011/05/19/9 http://viewvc.tigris.org/issues/show_bug.cgi?id=433 http://viewvc.tigris.org/source/browse/checkout/viewvc/tags/1.1.11/CHANGES http://viewvc.tigris.org/source/browse/viewvc/trunk/lib/cvsdb.py?diff_format=u&view=logrev2547 http://viewvc.tigris.org/source/browse/viewvc/trunk/lib/viewvc.py?diff_format=u&r1=2547&r2=2546&pathrev=2547 http://www.debian.org/security/2012/dsa-2563 http://www.securityfocus.com/bid/47928
Share on: