PT-2004-1852 · Cvs · Cvs

Published

2004-08-18

·

Updated

2024-02-14

·

CVE-2004-0778

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions CVS versions 1.11.x through 1.11.16 CVS versions 1.12.x through 1.12.8
Description The issue allows remote attackers to determine the existence of arbitrary files and directories. This is achieved via the -X command for an alternate history file, which causes different error messages to be returned, thus revealing the presence of specific files or directories.
Recommendations For CVS versions 1.11.x through 1.11.16, update to version 1.11.17 or later. For CVS versions 1.12.x through 1.12.8, update to version 1.12.9 or later.

Fix

Side Channel Attack

Weakness Enumeration

Related Identifiers

CVE-2004-0778
RHSA-2004:233

Affected Products

Cvs