CVE-2002-0844: High severity Derek Price Cvsd vulnerability
Published Aug 12, 2002
·Updated
Off-by-one overflow in the CVS PreservePermissions of rcs.c for CVSD before 1.11.2 allows local users to execute arbitrary code.
Affected Software
2 affected components
Derek Price Cvsd=1.11.2
Distrotech Cvs<1.11.2
Remediation
Patch Available
Event History
Aug 12, 2002
CVE Published
04:00 AM
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0844?
CVE-2002-0844 has a high severity level due to its ability to allow local users to execute arbitrary code.
2
How do I fix CVE-2002-0844?
To fix CVE-2002-0844, upgrade to CVSD version 1.11.2 or later.
3
Which versions of CVSD are affected by CVE-2002-0844?
CVE-2002-0844 affects all versions of CVSD prior to version 1.11.2.
4
Can CVE-2002-0844 be exploited remotely?
CVE-2002-0844 typically requires local access to the system, thus it is not an issue that can be exploited remotely.
5
Who is affected by CVE-2002-0844?
Local users on systems running affected versions of CVSD before 1.11.2 are at risk from CVE-2002-0844.