CVE-2004-0418: Critical severity Openpkg Openpkg vulnerability
Published Jun 11, 2004
·Updated
servenotify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote attackers to perform an "out-of-bounds" write for a single byte to execute arbitrary code or modify critical program data.
Affected Software
29 affected components
Openpkg Openpkg=2.0
CVS CVS=1.11.14
CVS CVS=1.11.1
CVS CVS=1.11
CVS CVS=1.12.2
CVS CVS=1.11.4
CVS CVS=1.12.7
Sgi Propack=3.0
CVS CVS=1.12.5
Openpkg Openpkg=1.3
CVS CVS=1.11.16
CVS CVS=1.11.5
CVS CVS=1.10.8
CVS CVS=1.11.15
CVS CVS=1.11.11
CVS CVS=1.12.8
CVS CVS=1.11.6
CVS CVS=1.12.1
CVS CVS=1.11.3
CVS CVS=1.11.2
CVS CVS=1.11.10
Sgi Propack=2.4
Openpkg Openpkg
CVS CVS=1.10.7
CVS CVS=1.11.1_p1
Gentoo Linux=1.4
OpenBSD OpenBSD=3.5
OpenBSD OpenBSD
OpenBSD OpenBSD=3.4
Remediation
Patch Available
Event History
Jun 11, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0418?
CVE-2004-0418 has a critical severity level due to its potential to execute arbitrary code.
2
How do I fix CVE-2004-0418?
To mitigate CVE-2004-0418, upgrade to a patched version of CVS beyond 1.12.8 or 1.11.16.
3
What versions of CVS are affected by CVE-2004-0418?
CVE-2004-0418 affects CVS versions 1.12.x up to 1.12.8 and 1.11.x up to 1.11.16.
4
What type of attack does CVE-2004-0418 allow?
CVE-2004-0418 allows remote attackers to perform an out-of-bounds write, potentially leading to arbitrary code execution.
5
Is CVE-2004-0418 specifically a local or remote vulnerability?
CVE-2004-0418 is a remote vulnerability that can be exploited over the network.