Vulnerability Name:

CVE-2005-0753 (CCN-20148)

Assigned:2005-04-18
Published:2005-04-18
Updated:2017-10-11
Summary:Buffer overflow in CVS before 1.11.20 allows remote attackers to execute arbitrary code.
CVSS v3 Severity:7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Access
References:Source: CCN
Type: FreeBSD Security Advisory FreeBSD-SA-05:05.cvs
Multiple vulnerabilities in CVS

Source: MISC
Type: Vendor Advisory
http://bugs.gentoo.org/attachment.cgi?id=54352&action=view

Source: MITRE
Type: CNA
CVE-2005-0753

Source: CCN
Type: Conectiva Linux Security Announcement CLSA-2005:966
Fixes for security vulnerabilities

Source: CCN
Type: RHSA-2005-387
cvs security update

Source: CCN
Type: SA14976
CVS Buffer Overflow and Denial of Service Vulnerabilities

Source: SECUNIA
Type: Patch, Vendor Advisory
14976

Source: CCN
Type: Concurrent Versions System (CVS)
CVS Home

Source: DEBIAN
Type: UNKNOWN
DSA-742

Source: DEBIAN
Type: DSA-742
cvs -- buffer overflow

Source: CCN
Type: GLSA-200504-16
CVS: Multiple vulnerabilities

Source: GENTOO
Type: Patch, Vendor Advisory
GLSA-200504-16

Source: SUSE
Type: Patch, Vendor Advisory
SUSE-SA:2005:024

Source: REDHAT
Type: Patch, Vendor Advisory
RHSA-2005:387

Source: CCN
Type: BID-13217
CVS Unspecified Buffer Overflow And Memory Access Vulnerabilities

Source: CCN
Type: TLSA-2005-51
Buffer overflow vulnerability exists in cvs

Source: CCN
Type: USN-117-1
cvs vulnerability

Source: CCN
Type: Concurrent Version System Document Web page
Documents & files

Source: CCN
Type: CVS Version Control
ccvs/News file

Source: XF
Type: UNKNOWN
cvs-bo(20148)

Source: XF
Type: UNKNOWN
cvs-bo(20148)

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:9688

Source: SUSE
Type: SUSE-SA:2005:024
cvs: remote code execution

Source: SUSE
Type: SUSE-SR:2005:012
SUSE Security Summary Report

Vulnerable Configuration:Configuration 1:
  • cpe:/a:cvs:cvs:1.10:*:*:*:*:*:*:*
  • OR cpe:/a:cvs:cvs:1.10.6:*:*:*:*:*:*:*
  • OR cpe:/a:cvs:cvs:1.10.7:*:*:*:*:*:*:*
  • OR cpe:/a:cvs:cvs:1.10.8:*:*:*:*:*:*:*
  • OR cpe:/a:cvs:cvs:1.11:*:*:*:*:*:*:*
  • OR cpe:/a:cvs:cvs:1.11.1:*:*:*:*:*:*:*
  • OR cpe:/a:cvs:cvs:1.11.1_p1:*:*:*:*:*:*:*
  • OR cpe:/a:cvs:cvs:1.11.2:*:*:*:*:*:*:*
  • OR cpe:/a:cvs:cvs:1.11.3:*:*:*:*:*:*:*
  • OR cpe:/a:cvs:cvs:1.11.4:*:*:*:*:*:*:*
  • OR cpe:/a:cvs:cvs:1.11.5:*:*:*:*:*:*:*
  • OR cpe:/a:cvs:cvs:1.11.6:*:*:*:*:*:*:*
  • OR cpe:/a:cvs:cvs:1.11.10:*:*:*:*:*:*:*
  • OR cpe:/a:cvs:cvs:1.11.11:*:*:*:*:*:*:*
  • OR cpe:/a:cvs:cvs:1.11.14:*:*:*:*:*:*:*
  • OR cpe:/a:cvs:cvs:1.11.15:*:*:*:*:*:*:*
  • OR cpe:/a:cvs:cvs:1.11.16:*:*:*:*:*:*:*

  • Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:*:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:9688
    V
    Buffer overflow in CVS before 1.11.20 allows remote attackers to execute arbitrary code.
    2013-04-29
    oval:org.debian:def:742
    V
    buffer overflow
    2005-07-07
    oval:com.redhat.rhsa:def:20050387
    P
    RHSA-2005:387: cvs security update (Moderate)
    2005-04-25
    BACK
    cvs cvs 1.10
    cvs cvs 1.10.6
    cvs cvs 1.10.7
    cvs cvs 1.10.8
    cvs cvs 1.11
    cvs cvs 1.11.1
    cvs cvs 1.11.1_p1
    cvs cvs 1.11.2
    cvs cvs 1.11.3
    cvs cvs 1.11.4
    cvs cvs 1.11.5
    cvs cvs 1.11.6
    cvs cvs 1.11.10
    cvs cvs 1.11.11
    cvs cvs 1.11.14
    cvs cvs 1.11.15
    cvs cvs 1.11.16