PT-2004-1557 · Cvs · Cvs
Sebastian Krahmer
+1
·
Published
2004-06-11
·
Updated
2018-05-03
·
CVE-2004-0418
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
cvs versions 1.12.x through 1.12.8
cvs versions 1.11.x through 1.11.16
Description
The issue is related to the serve notify function, which does not properly handle empty data lines. This may allow remote attackers to perform an out-of-bounds write for a single byte, potentially leading to the execution of arbitrary code or modification of critical program data.
Recommendations
For cvs versions 1.12.x through 1.12.8, update to a version that fixes the serve notify function issue.
For cvs versions 1.11.x through 1.11.16, update to a version that fixes the serve notify function issue.
As a temporary workaround, consider restricting access to the serve notify function until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cvs