CVE-2004-0778

CVS <1.11.17-1.12.9 - Info Disclosure

Title source: llm
STIX 2.1

Description

CVS 1.11.x before 1.11.17, and 1.12.x before 1.12.9, allows remote attackers to determine the existence of arbitrary files and directories via the -X command for an alternate history file, which causes different error messages to be returned.

References (6)

Core 6
Core References
Broken Link, Patch, Third Party Advisory, VDB Entry, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/10955
Broken Link vendor-advisory x_refsource_mandrake
http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:108
Broken Link, Vendor Advisory third-party-advisory x_refsource_idefense
http://www.idefense.com/application/poi/display?id=130&type=vulnerabilities
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/17001
Patch, Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/579225

Scores

EPSS 0.0406
EPSS Percentile 88.7%

Details

CWE
CWE-203
Status published
Products (1)
gnu/cvs 1.11.0 - 1.11.17
Published Oct 20, 2004
Tracked Since Feb 18, 2026