PT-2004-1557 · Cvs · Cvs

Sebastian Krahmer

+1

·

Publicado

2004-06-11

·

Atualizado

2018-05-03

·

CVE-2004-0418

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions cvs versions 1.12.x through 1.12.8 cvs versions 1.11.x through 1.11.16
Description The issue is related to the serve notify function, which does not properly handle empty data lines. This may allow remote attackers to perform an out-of-bounds write for a single byte, potentially leading to the execution of arbitrary code or modification of critical program data.
Recommendations For cvs versions 1.12.x through 1.12.8, update to a version that fixes the serve notify function issue. For cvs versions 1.11.x through 1.11.16, update to a version that fixes the serve notify function issue. As a temporary workaround, consider restricting access to the serve notify function until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-0418
DSA-519
RHSA-2004:233

Produtos afetados

Cvs