PT-2012-1022 · Debian+3 · Cvs+3

Vincent Danen

·

Publicado

2012-02-21

·

Atualizado

2024-06-15

·

CVE-2012-0804

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions CVS versions 1.11 through 1.12
Description The issue concerns multiple vulnerabilities in the CVS package of the Debian GNU/Linux operating system, which can be exploited remotely to compromise the confidentiality, integrity, and availability of protected information. Specifically, a heap-based buffer overflow in the proxy connect function in src/client.c can cause a denial of service (crash) and possibly allow the execution of arbitrary code via a crafted HTTP response.
Recommendations For CVS versions 1.11 through 1.12, consider disabling the proxy connect function as a temporary workaround until a patch is available. Restrict access to the CVS service to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-01323
CESA-2012_0321
CVE-2012-0804
DSA-2407-1
OPENSUSE-SU-2024:10504-1
RHSA-2012:0321
RHSA-2012_0321
SUSE-SU-2012_0311-1

Produtos afetados

Cvs
Centos
Red Hat
Suse