CVE-2002-0092: Medium severity cvs cvs vulnerability
Published Mar 15, 2002
·Updated
CVS before 1.10.8 does not properly initialize a global variable, which allows remote attackers to cause a denial of service (server crash) via the diff capability.
Affected Software
1 affected component
CVS CVS<=1.10.8
Remediation
Patch Available
Event History
Mar 15, 2002
CVE Published
05:00 AM
Jun 25, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0092?
CVE-2002-0092 is classified as a denial of service vulnerability that can lead to server crashes.
2
How do I fix CVE-2002-0092?
To fix CVE-2002-0092, upgrade CVS to version 1.10.8 or later.
3
What software is affected by CVE-2002-0092?
CVS versions before 1.10.8 are affected by CVE-2002-0092.
4
Can CVE-2002-0092 be exploited remotely?
Yes, CVE-2002-0092 can be exploited by remote attackers using the diff capability.
5
What should I do if I cannot upgrade CVS for CVE-2002-0092?
If you cannot upgrade CVS, consider implementing network access controls to limit exposure to the vulnerability.