First published: Sun Apr 23 2000(Updated: )
Concurrent Versions Software (CVS) uses predictable temporary file names for locking, which allows local users to cause a denial of service by creating the lock directory before it is created for use by a legitimate CVS user.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Concurrent Versions Software | ||
Distrotech Cvs | =1.10.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0338 is classified as a vulnerability that can lead to a denial of service due to predictable temporary file names.
To fix CVE-2000-0338, users should upgrade to a newer version of CVS that mitigates the use of predictable temporary file names.
Local users on systems running affected versions of Concurrent Versions Software, such as CVS 1.10.7, are vulnerable to CVE-2000-0338.
CVE-2000-0338 allows local users to disrupt legitimate CVS operations by creating a lock directory before a legitimate user can.
CVE-2000-0338 specifically affects CVS version 1.10.7.