First published: Fri Dec 31 2004(Updated: )
CVS 1.12 and earlier on Debian GNU/Linux does not properly handle when a mapping for the current repository does not exist in the cvs-repouids file, which allows remote attackers to cause a denial of service (server crash).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Distrotech Cvs | =1.11.14 | |
Distrotech Cvs | =1.10.6 | |
Distrotech Cvs | =1.11.1 | |
Distrotech Cvs | =1.11 | |
Distrotech Cvs | =1.11.4 | |
Distrotech Cvs | =1.11.16 | |
Distrotech Cvs | =1.11.5 | |
Distrotech Cvs | =1.10.8 | |
Distrotech Cvs | =1.11.15 | |
Distrotech Cvs | =1.11.11 | |
Distrotech Cvs | =1.11.6 | |
Distrotech Cvs | =1.10 | |
Distrotech Cvs | =1.11.3 | |
Distrotech Cvs | =1.11.2 | |
Distrotech Cvs | =1.11.10 | |
Distrotech Cvs | =1.12 | |
Distrotech Cvs | =1.10.7 | |
Distrotech Cvs | =1.11.1_p1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1343 has been classified as a denial of service vulnerability.
To fix CVE-2004-1343, upgrade to CVS version 1.12 or later.
CVEs 1.10.x and 1.11.x versions of CVS prior to 1.12 are affected by CVE-2004-1343.
Yes, CVE-2004-1343 can be exploited remotely to cause a denial of service.
Debian GNU/Linux systems running CVS 1.12 and earlier are impacted by CVE-2004-1343.