First published: Mon Jan 23 2012(Updated: )
Heap-based buffer overflow in the proxy_connect function in src/client.c in CVS 1.11 and 1.12 allows remote HTTP proxy servers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted HTTP response.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Distrotech Cvs | =1.11 | |
Distrotech Cvs | =1.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0804 is classified as a high severity vulnerability due to the potential for denial of service and arbitrary code execution.
To remediate CVE-2012-0804, upgrade to versions 1.11.23 or 1.12.13 of CVS which contain the necessary patches.
CVE-2012-0804 affects CVS versions 1.11 and 1.12 specifically.
CVE-2012-0804 is a heap-based buffer overflow vulnerability.
Yes, CVE-2012-0804 can be exploited remotely by sending a crafted HTTP response through a proxy.