Vulnerability Name:

CVE-2004-0405 (CCN-15891)

Assigned:2004-04-14
Published:2004-04-14
Updated:2017-10-11
Summary:CVS before 1.11 allows CVS clients to read arbitrary files via .. (dot dot) sequences in filenames via CVS client requests, a different vulnerability than CVE-2004-0180.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-Other
Vulnerability Consequences:File Manipulation
References:Source: FREEBSD
Type: Patch, Vendor Advisory
FreeBSD-SA-04:07

Source: SGI
Type: Patch, Vendor Advisory
20040404-01-U

Source: MITRE
Type: CNA
CVE-2004-0405

Source: FEDORA
Type: UNKNOWN
FEDORA-2004-1620

Source: CCN
Type: RHSA-2004-153
cvs security update

Source: CCN
Type: RHSA-2004-154
Updated CVS packages fix security issue

Source: GENTOO
Type: UNKNOWN
GLSA-200404-13

Source: DEBIAN
Type: Patch, Vendor Advisory
DSA-486

Source: DEBIAN
Type: DSA-486
cvs -- several vulnerabilities

Source: CCN
Type: GLSA-200404-13
CVS Server and Client Vulnerabilities

Source: CCN
Type: BID-10140
CVS Server Piped Checkout Access Validation Vulnerability

Source: SLACKWARE
Type: UNKNOWN
SSA:2004-108-02

Source: CCN
Type: slackware-security Mailing List, Sun, 18 Apr 2004 16:40:41 -0700 (PDT)
cvs security update (SSA:2004-108-02)

Source: XF
Type: UNKNOWN
cvs-dotdot-directory-traversal(15891)

Source: XF
Type: UNKNOWN
cvs-dotdot-directory-traversal(15891)

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:1060

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:10818

Vulnerable Configuration:Configuration 1:
  • cpe:/a:cvs:cvs:*:*:*:*:*:*:*:* (Version <= 1.10)

  • Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:*:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:10818
    V
    CVS before 1.11 allows CVS clients to read arbitrary files via .. (dot dot) sequences in filenames via CVS client requests, a different vulnerability than CVE-2004-0180.
    2013-04-29
    oval:org.mitre.oval:def:1060
    V
    Directory Traversal Vulnerability in CVS Server
    2007-04-25
    oval:com.redhat.rhsa:def:20040153
    P
    RHSA-2004:153: cvs security update (Moderate)
    2004-04-17
    oval:org.debian:def:486
    V
    several vulnerabilities
    2004-04-16
    BACK
    cvs cvs *