20040519 Advisory 07/2004: CVS remote vulnerabilitymailing list
http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0980.html CVE-2004-0396
CVS (Linux/FreeBSD) - Remote Entry Line Heap Overflow
Record summary
CVE-2004-0396 has a selected CVSS score of 7.5; EIP currently links 2 catalogued exploits.
Description
Heap-based buffer overflow in CVS 1.11.x up to 1.11.15, and 1.12.x up to 1.12.7, when using the pserver mechanism allows remote attackers to execute arbitrary code via Entry lines.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBCVS (Linux/FreeBSD) - Remote Entry Line Heap OverflowExploitDB exploitby Ac1dB1tCh3zNot analyzed1 file
ExploitDBCVS - Remote Entry Line Root Heap OverflowExploitDB exploitby anonymousNot analyzed1 file
References
Showing 12 of 2720040519 Advisory 07/2004: CVS remote vulnerabilitymailing list
http://cert.uni-stuttgart.de/archive/bugtraq/2004/05/msg00219.html SuSE-SA:2004:013Vendor advisory
http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021742.html 20040519 Advisory 07/2004: CVS remote vulnerabilitymailing list
http://marc.info/?l=bugtraq&m=108498454829020&w=2 20040519 [OpenPKG-SA-2004.022] OpenPKG Security Advisory (cvs)mailing list
http://marc.info/?l=bugtraq&m=108500040719512&w=2 FEDORA-2004-1620Vendor advisory
http://marc.info/?l=bugtraq&m=108636445031613&w=2 20040520 cvs server buffer overflow vulnerabilityVendor advisory
http://marc.info/?l=openbsd-security-announce&m=108508894405639&w=2 11641Third-party advisory
http://secunia.com/advisories/11641 11647Third-party advisory
http://secunia.com/advisories/11647 11651Third-party advisory
http://secunia.com/advisories/11651 11652Third-party advisory
http://secunia.com/advisories/11652 11674Third-party advisory
http://secunia.com/advisories/11674