PT-2004-1852 · Cvs · Cvs
Published
2004-08-18
·
Updated
2024-02-14
·
CVE-2004-0778
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
CVS versions 1.11.x through 1.11.16
CVS versions 1.12.x through 1.12.8
Description
The issue allows remote attackers to determine the existence of arbitrary files and directories. This is achieved via the -X command for an alternate history file, which causes different error messages to be returned, thus revealing the presence of specific files or directories.
Recommendations
For CVS versions 1.11.x through 1.11.16, update to version 1.11.17 or later.
For CVS versions 1.12.x through 1.12.8, update to version 1.12.9 or later.
Fix
Side Channel Attack
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cvs