CVE-2000-0680: High severity cvs cvs vulnerability
The CVS 1.10.8 server does not properly restrict users from creating arbitrary Checkin.prog or Update.prog programs, which allows remote CVS committers to modify or create Trojan horse programs with the Checkin.prog or Update.prog names, then performing a CVS commit action.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0680?
CVE-2000-0680 has a moderate severity level due to the potential for remote users to create malicious programs.
How do I fix CVE-2000-0680?
To fix CVE-2000-0680, upgrade the CVS server to a version beyond 1.10.8 where this vulnerability has been addressed.
What type of software is affected by CVE-2000-0680?
CVE-2000-0680 specifically affects CVS version 1.10.8.
What impact does CVE-2000-0680 have on my system?
CVE-2000-0680 allows unauthorized modification or creation of programs, potentially leading to malicious exploitation.
Can CVE-2000-0680 be exploited remotely?
Yes, CVE-2000-0680 can be exploited remotely by CVS committers who have access to the server.