Unrated severityNVD Advisory· Published May 5, 2009· Updated Apr 23, 2026
CVE-2009-0148
CVE-2009-0148
Description
Multiple buffer overflows in Cscope before 15.7a allow remote attackers to execute arbitrary code via long strings in input such as (1) source-code tokens and (2) pathnames, related to integer overflows in some cases. NOTE: this issue exists because of an incomplete fix for CVE-2004-2541.
Affected products
8cpe:2.3:a:cscope:cscope:13.0:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:cscope:cscope:13.0:*:*:*:*:*:*:*
- cpe:2.3:a:cscope:cscope:15.0bl2:*:*:*:*:*:*:*
- cpe:2.3:a:cscope:cscope:15.1:*:*:*:*:*:*:*
- cpe:2.3:a:cscope:cscope:15.3:*:*:*:*:*:*:*
- cpe:2.3:a:cscope:cscope:15.4:*:*:*:*:*:*:*
- cpe:2.3:a:cscope:cscope:15.5:*:*:*:*:*:*:*
- cpe:2.3:a:cscope:cscope:15.6:*:*:*:*:*:*:*
- cpe:2.3:a:cscope:cscope:15.7:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
22- sourceforge.net/forum/forum.phpnvdPatch
- sourceforge.net/project/shownotes.phpnvdPatch
- secunia.com/advisories/34978nvdVendor Advisory
- secunia.com/advisories/35074nvdVendor Advisory
- secunia.com/advisories/35213nvdVendor Advisory
- secunia.com/advisories/35214nvdVendor Advisory
- secunia.com/advisories/35462nvdVendor Advisory
- www.vupen.com/english/advisories/2009/1238nvdVendor Advisory
- www.vupen.com/english/advisories/2009/1297nvdVendor Advisory
- www.us-cert.gov/cas/techalerts/TA09-133A.htmlnvdUS Government Resource
- lists.apple.com/archives/security-announce/2009/May/msg00002.htmlnvd
- security.gentoo.org/glsa/glsa-200905-02.xmlnvd
- sourceforge.net/mailarchive/forum.phpnvd
- support.apple.com/kb/HT3549nvd
- www.debian.org/security/2009/dsa-1806nvd
- www.openwall.com/lists/oss-security/2009/05/06/9nvd
- www.redhat.com/support/errata/RHSA-2009-1101.htmlnvd
- www.redhat.com/support/errata/RHSA-2009-1102.htmlnvd
- www.securityfocus.com/bid/34805nvd
- www.securitytracker.com/idnvd
- bugzilla.redhat.com/show_bug.cginvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9633nvd
News mentions
0No linked articles in our index yet.