Vulnerability Name: | CVE-2003-0977 (CCN-13929) | ||||||||||||||||||||||||
Assigned: | 2003-12-08 | ||||||||||||||||||||||||
Published: | 2003-12-08 | ||||||||||||||||||||||||
Updated: | 2017-10-11 | ||||||||||||||||||||||||
Summary: | CVS server before 1.11.10 may allow attackers to cause the CVS server to create directories and files in the file system root directory via malformed module requests. | ||||||||||||||||||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||||||||||
Vulnerability Consequences: | File Manipulation | ||||||||||||||||||||||||
References: | Source: SGI Type: UNKNOWN 20040103-01-U Source: SGI Type: UNKNOWN 20040202-01-U Source: CCN Type: Concurrent Versions System Web site Stable CVS Version 1.11.10 Released! (security update) Source: CONFIRM Type: Patch http://ccvs.cvshome.org/servlets/NewsItemView?newsID=84&JServSessionIdservlets=8u3x1myav1 Source: MITRE Type: CNA CVE-2003-0977 Source: CONECTIVA Type: UNKNOWN CLA-2004:808 Source: CCN Type: Conectiva Linux Security Announcement CLSA-2004:808 cvs Source: BUGTRAQ Type: UNKNOWN 20031217 [OpenPKG-SA-2003.052] OpenPKG Security Advisory (cvs) Source: BUGTRAQ Type: UNKNOWN 20040129 [FLSA-2004:1207] Updated cvs resolves security vulnerability Source: CCN Type: RHSA-2004-003 Updated CVS packages fix minor security issue Source: CCN Type: RHSA-2004-004 cvs security update Source: SECUNIA Type: UNKNOWN 10601 Source: CCN Type: CIAC Information Bulletin O-049 Red Hat Updated CVS Packages Fix Minor Security Issue Source: DEBIAN Type: Patch, Vendor Advisory DSA-422 Source: DEBIAN Type: DSA-422 cvs -- remote vulnerability Source: CCN Type: GLSA-200312-04 CVS: malformed module request vulnerability Source: CCN Type: Gentoo Linux Security Announcement 200312-04 dev-util/cvs Source: MANDRAKE Type: UNKNOWN MDKSA-2003:112 Source: CCN Type: OpenPKG-SA-2003.052 CVS Source: REDHAT Type: UNKNOWN RHSA-2004:003 Source: REDHAT Type: UNKNOWN RHSA-2004:004 Source: CCN Type: BID-9178 CVS Malformed Request System Root File Creation Vulnerability Source: CCN Type: slackware-security Mailing List, Thu, 11 Dec 2003 13:52:45 -0800 (PST) cvs security update (SSA:2003-345-01) Source: CCN Type: TLSA-2003-69 CVS server to create files and directories in the file system root directory Source: XF Type: UNKNOWN cvs-module-file-manipulation(13929) Source: XF Type: UNKNOWN cvs-module-file-manipulation(13929) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:11528 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:855 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:866 | ||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration RedHat 1: ![]() | ||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
BACK |