First published: Fri Apr 16 2004(Updated: )
The client for CVS before 1.11 allows a remote malicious CVS server to create arbitrary files using certain RCS diff files that use absolute pathnames during checkouts or updates, a different vulnerability than CVE-2004-0405.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Distrotech Cvs | <=1.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0180 is considered a high-severity vulnerability due to its potential for arbitrary file creation on the client system.
To fix CVE-2004-0180, upgrade to CVS version 1.11 or later, which mitigates the vulnerability.
CVE-2004-0180 affects CVS versions prior to 1.11, specifically those that are vulnerable to malicious RCS diff files.
CVE-2004-0180 exploits the CVS client by allowing a malicious CVS server to specify absolute pathnames in RCS diff files, leading to arbitrary file creation.
While CVE-2004-0180 is an older vulnerability, it remains a concern for legacy systems that have not been upgraded to secure versions.