PT-2004-1557 · Cvs · Cvs

Sebastian Krahmer

+1

·

Published

2004-06-11

·

Updated

2018-05-03

·

CVE-2004-0418

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions cvs versions 1.12.x through 1.12.8 cvs versions 1.11.x through 1.11.16
Description The issue is related to the serve notify function, which does not properly handle empty data lines. This may allow remote attackers to perform an out-of-bounds write for a single byte, potentially leading to the execution of arbitrary code or modification of critical program data.
Recommendations For cvs versions 1.12.x through 1.12.8, update to a version that fixes the serve notify function issue. For cvs versions 1.11.x through 1.11.16, update to a version that fixes the serve notify function issue. As a temporary workaround, consider restricting access to the serve notify function until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-0418
DSA-519
RHSA-2004:233

Affected Products

Cvs