Vulnerability Name: | CVE-2004-0405 (CCN-15891) | ||||||||||||||||||||
Assigned: | 2004-04-14 | ||||||||||||||||||||
Published: | 2004-04-14 | ||||||||||||||||||||
Updated: | 2017-10-11 | ||||||||||||||||||||
Summary: | CVS before 1.11 allows CVS clients to read arbitrary files via .. (dot dot) sequences in filenames via CVS client requests, a different vulnerability than CVE-2004-0180. | ||||||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||||||
Vulnerability Consequences: | File Manipulation | ||||||||||||||||||||
References: | Source: FREEBSD Type: Patch, Vendor Advisory FreeBSD-SA-04:07 Source: SGI Type: Patch, Vendor Advisory 20040404-01-U Source: MITRE Type: CNA CVE-2004-0405 Source: FEDORA Type: UNKNOWN FEDORA-2004-1620 Source: CCN Type: RHSA-2004-153 cvs security update Source: CCN Type: RHSA-2004-154 Updated CVS packages fix security issue Source: GENTOO Type: UNKNOWN GLSA-200404-13 Source: DEBIAN Type: Patch, Vendor Advisory DSA-486 Source: DEBIAN Type: DSA-486 cvs -- several vulnerabilities Source: CCN Type: GLSA-200404-13 CVS Server and Client Vulnerabilities Source: CCN Type: BID-10140 CVS Server Piped Checkout Access Validation Vulnerability Source: SLACKWARE Type: UNKNOWN SSA:2004-108-02 Source: CCN Type: slackware-security Mailing List, Sun, 18 Apr 2004 16:40:41 -0700 (PDT) cvs security update (SSA:2004-108-02) Source: XF Type: UNKNOWN cvs-dotdot-directory-traversal(15891) Source: XF Type: UNKNOWN cvs-dotdot-directory-traversal(15891) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:1060 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:10818 | ||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Denotes that component is vulnerable | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |