First published: Thu May 20 2004(Updated: )
Heap-based buffer overflow in CVS 1.11.x up to 1.11.15, and 1.12.x up to 1.12.7, when using the pserver mechanism allows remote attackers to execute arbitrary code via Entry lines.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Distrotech Cvs | =1.11 | |
Distrotech Cvs | =1.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0396 is rated as high severity due to its potential to allow remote code execution.
To fix CVE-2004-0396, upgrade CVS to versions 1.11.16 or higher, or 1.12.8 or higher.
CVEs 1.11.x up to 1.11.15 and 1.12.x up to 1.12.7 are affected by CVE-2004-0396.
CVE-2004-0396 is a heap-based buffer overflow vulnerability in the CVS client.
Yes, CVE-2004-0396 can be exploited remotely through the pserver mechanism.