First published: Mon Aug 12 2002(Updated: )
Off-by-one overflow in the CVS PreservePermissions of rcs.c for CVSD before 1.11.2 allows local users to execute arbitrary code.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Derek Price Cvsd | =1.11.2 | |
Distrotech Cvs | <1.11.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0844 has a high severity level due to its ability to allow local users to execute arbitrary code.
To fix CVE-2002-0844, upgrade to CVSD version 1.11.2 or later.
CVE-2002-0844 affects all versions of CVSD prior to version 1.11.2.
CVE-2002-0844 typically requires local access to the system, thus it is not an issue that can be exploited remotely.
Local users on systems running affected versions of CVSD before 1.11.2 are at risk from CVE-2002-0844.