PT-2012-1022 · Debian+3 · Cvs+3
Vincent Danen
·
Published
2012-02-21
·
Updated
2024-06-15
·
CVE-2012-0804
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
CVS versions 1.11 through 1.12
Description
The issue concerns multiple vulnerabilities in the CVS package of the Debian GNU/Linux operating system, which can be exploited remotely to compromise the confidentiality, integrity, and availability of protected information. Specifically, a heap-based buffer overflow in the
proxy connect function in src/client.c can cause a denial of service (crash) and possibly allow the execution of arbitrary code via a crafted HTTP response.Recommendations
For CVS versions 1.11 through 1.12, consider disabling the
proxy connect function as a temporary workaround until a patch is available. Restrict access to the CVS service to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cvs
Centos
Red Hat
Suse