CVE-2009-0148

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
05/05/2009
Last modified:
09/04/2025

Description

Multiple buffer overflows in Cscope before 15.7a allow remote attackers to execute arbitrary code via long strings in input such as (1) source-code tokens and (2) pathnames, related to integer overflows in some cases. NOTE: this issue exists because of an incomplete fix for CVE-2004-2541.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cscope:cscope:13.0:*:*:*:*:*:*:*
cpe:2.3:a:cscope:cscope:15.0bl2:*:*:*:*:*:*:*
cpe:2.3:a:cscope:cscope:15.1:*:*:*:*:*:*:*
cpe:2.3:a:cscope:cscope:15.3:*:*:*:*:*:*:*
cpe:2.3:a:cscope:cscope:15.4:*:*:*:*:*:*:*
cpe:2.3:a:cscope:cscope:15.5:*:*:*:*:*:*:*
cpe:2.3:a:cscope:cscope:15.6:*:*:*:*:*:*:*
cpe:2.3:a:cscope:cscope:15.7:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools