Oval Definition:
oval:org.mitre.oval:def:970
Revision Date
:
2007-04-25
Version
:
19
Title
:
CVS pserver BO
Description
:
Heap-based buffer overflow in CVS 1.11.x up to 1.11.15, and 1.12.x up to 1.12.7, when using the pserver mechanism allows remote attackers to execute arbitrary code via Entry lines.
Family
:
unix
Class
:
vulnerability
Status
:
ACCEPTED
Reference(s)
:
CVE-2004-0396
Platform(s)
:
Red Hat Enterprise Linux 3
Product(s)
:
Definition Synopsis
Software section
Red Hat Enterprise 3 is installed
AND
ix86 architecture
AND
cvs version is less than 1.11.2-22
AND
Configuration section
/usr/bin/cvs is executable
/usr/bin/cvs is executable
OR
/usr/bin/cvs is executable
OR
/usr/bin/cvs is executable
BACK