PT-2004-1557 · Cvs · Cvs
Sebastian Krahmer
+1
·
Publicado
2004-06-11
·
Atualizado
2018-05-03
·
CVE-2004-0418
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
cvs versions 1.12.x through 1.12.8
cvs versions 1.11.x through 1.11.16
Description
The issue is related to the serve notify function, which does not properly handle empty data lines. This may allow remote attackers to perform an out-of-bounds write for a single byte, potentially leading to the execution of arbitrary code or modification of critical program data.
Recommendations
For cvs versions 1.12.x through 1.12.8, update to a version that fixes the serve notify function issue.
For cvs versions 1.11.x through 1.11.16, update to a version that fixes the serve notify function issue.
As a temporary workaround, consider restricting access to the serve notify function until a patch is available.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Cvs