Vulnerability Name: | CVE-2004-0417 (CCN-16369) | ||||||||||||||||||||||||
Assigned: | 2004-06-09 | ||||||||||||||||||||||||
Published: | 2004-06-09 | ||||||||||||||||||||||||
Updated: | 2018-05-03 | ||||||||||||||||||||||||
Summary: | Integer overflow in the "Max-dotdot" CVS protocol command (serve_max_dotdot) for CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to cause a server crash, which could cause temporary data to remain undeleted and consume disk space. | ||||||||||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||||||||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
| ||||||||||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||
References: | Source: CCN Type: FreeBSD Security Advisory FreeBSD-SA-04:14.cvs.asc cvs Source: SGI Type: UNKNOWN 20040605-01-U Source: CCN Type: Full-Disclosure Mailing List, Wed Jun 09 2004 - 08:00:04 CDT Advisory 09/2004: More CVS remote vulnerabilities Source: CCN Type: CVS Web site Project Download List Source: MITRE Type: CNA CVE-2004-0417 Source: FULLDISC Type: UNKNOWN 20040609 Advisory 09/2004: More CVS remote vulnerabilities Source: BUGTRAQ Type: UNKNOWN 20040611 [OpenPKG-SA-2004.027] OpenPKG Security Advisory (cvs) Source: CCN Type: RHSA-2004-233 cvs security update Source: MISC Type: UNKNOWN http://security.e-matters.de/advisories/092004.html Source: GENTOO Type: Vendor Advisory GLSA-200406-06 Source: CCN Type: Slackware Security Advisories (SSA:2004-161-01) cvs Source: CCN Type: CIAC Information Bulletin O-156 Multiple Vulnerabilities in CVS Source: DEBIAN Type: Patch, Vendor Advisory DSA-519 Source: DEBIAN Type: DSA-519 cvs -- several vulnerabilities Source: CCN Type: GLSA-200406-06 CVS: additional DoS and arbitrary code execution vulnerabilities Source: CCN Type: GLSA 200406-06 CVS: additional DoS and arbitrary code execution Source: MANDRAKE Type: UNKNOWN MDKSA-2004:058 Source: CCN Type: OpenPKG-SA-2004.027 CVS Source: REDHAT Type: UNKNOWN RHSA-2004:233 Source: CCN Type: BID-10499 CVS Multiple Vulnerabilities Source: XF Type: UNKNOWN cvs-argument-integer-bo(16369) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:1001 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:11145 Source: SUSE Type: SUSE-SA:2004:015 cvs: remote command execution | ||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration RedHat 1: Denotes that component is vulnerable | ||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
BACK |