Vulnerability Name: | CVE-2004-0418 (CCN-16367) | ||||||||||||||||||||||||
Assigned: | 2004-06-09 | ||||||||||||||||||||||||
Published: | 2004-06-09 | ||||||||||||||||||||||||
Updated: | 2018-05-03 | ||||||||||||||||||||||||
Summary: | serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote attackers to perform an "out-of-bounds" write for a single byte to execute arbitrary code or modify critical program data. | ||||||||||||||||||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||||||||||||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||
References: | Source: CCN Type: FreeBSD Security Advisory FreeBSD-SA-04:14.cvs.asc cvs Source: SGI Type: UNKNOWN 20040604-01-U Source: SGI Type: UNKNOWN 20040605-01-U Source: CCN Type: Full-Disclosure Mailing List, Wed Jun 09 2004 - 08:00:04 CDT Advisory 09/2004: More CVS remote vulnerabilities Source: CCN Type: CVS Web site Project Download List Source: MITRE Type: CNA CVE-2004-0418 Source: FULLDISC Type: UNKNOWN 20040609 Advisory 09/2004: More CVS remote vulnerabilities Source: BUGTRAQ Type: UNKNOWN 20040611 [OpenPKG-SA-2004.027] OpenPKG Security Advisory (cvs) Source: CCN Type: RHSA-2004-233 cvs security update Source: MISC Type: UNKNOWN http://security.e-matters.de/advisories/092004.html Source: GENTOO Type: Vendor Advisory GLSA-200406-06 Source: CCN Type: Slackware Security Advisories (SSA:2004-161-01) cvs Source: CCN Type: CIAC Information Bulletin O-156 Multiple Vulnerabilities in CVS Source: DEBIAN Type: Patch, Vendor Advisory DSA-519 Source: DEBIAN Type: DSA-519 cvs -- several vulnerabilities Source: CCN Type: GLSA-200406-06 CVS: additional DoS and arbitrary code execution vulnerabilities Source: CCN Type: GLSA 200406-06 CVS: additional DoS and arbitrary code execution Source: MANDRAKE Type: UNKNOWN MDKSA-2004:058 Source: CCN Type: OpenPKG-SA-2004.027 CVS Source: REDHAT Type: UNKNOWN RHSA-2004:233 Source: CCN Type: BID-10499 CVS Multiple Vulnerabilities Source: XF Type: UNKNOWN cvs-servenotify-empty-bo(16367) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:1003 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:11242 Source: SUSE Type: SUSE-SA:2004:015 cvs: remote command execution | ||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration RedHat 1: Denotes that component is vulnerable | ||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
BACK |