Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> General >> CVS malformed entry lines flaw


Vulnerability Assessment Details

CVS malformed entry lines flaw

Vulnerability Assessment Summary
Logs into the remote CVS server and asks the version

Detailed Explanation for this Vulnerability Assessment

Summary :

The remote CVS server is affected by multiple issues.

Description :

The remote CVS server, according to its version number, might permit an
attacker to execute arbitrary commands on the remote system because of
a flaw relating to malformed Entry lines which lead to a missing NULL
terminator.

Among the issues deemed likely to be exploitable were:

- a double-free relating to the error_prog_name string (CVE-2004-0416)
- an argument integer overflow (CVE-2004-0417)
- out-of-bounds writes in serv_notify (CVE-2004-0418)

See also :

http://lists.grok.org.uk/pipermail/full-disclosure/2004-June/022441.html

Solution :

Upgrade to CVS 1.12.9 or 1.11.17

Network Security Threat Level:

Medium / CVSS Base Score : 4
(AV:R/AC:L/Au:R/C:P/A:P/I:P/B:N)

Networks Security ID: 10499

Vulnerability Assessment Copyright: This script is Copyright (C) 2004 David Maciejak

Cables, Connectors


Cisco Nexus 48-Port 10G SFP+ Switch N9K-9396PX w/ 9K-M12PQ 12-Port 40G QSFP picture

Cisco Nexus 48-Port 10G SFP+ Switch N9K-9396PX w/ 9K-M12PQ 12-Port 40G QSFP

$249.99



Cisco 2900 Series CISCO2911/K9 Integrated Services Router picture

Cisco 2900 Series CISCO2911/K9 Integrated Services Router

$46.74



Cisco C9200L-24P-4G-A Catalyst 9200L 24P PoE+ 4x1G Uplink Switch 1 Year Warranty picture

Cisco C9200L-24P-4G-A Catalyst 9200L 24P PoE+ 4x1G Uplink Switch 1 Year Warranty

$1845.00



Cisco Catalyst 3850 48 PoE+ 48-Port Gigabit Managed Switch WS-C3850-48F-E picture

Cisco Catalyst 3850 48 PoE+ 48-Port Gigabit Managed Switch WS-C3850-48F-E

$150.00



Cisco WS-C3850-48P-L 48-Port Gigabit 3850 PoE Switch w/ 715W+ C3850-NM-4-1G Mod picture

Cisco WS-C3850-48P-L 48-Port Gigabit 3850 PoE Switch w/ 715W+ C3850-NM-4-1G Mod

$83.00



Cisco Nexus N9K-C93180YC-EX 48-Port 1/10/25G SFP + 6 40G/100G QSFP28 Switch picture

Cisco Nexus N9K-C93180YC-EX 48-Port 1/10/25G SFP + 6 40G/100G QSFP28 Switch

$789.00



Cisco C3850-NM-2-10G 2 Port Network Exp.Module for 3850 picture

Cisco C3850-NM-2-10G 2 Port Network Exp.Module for 3850

$38.99



Genuine Cisco SFP-10G-SR V03 10GBASE-SR SFP+ Transceiver Module 10-2415-03  picture

Genuine Cisco SFP-10G-SR V03 10GBASE-SR SFP+ Transceiver Module 10-2415-03

$8.00



Cisco Catalyst 3850 WS-C3850-48U-S 48-Port UPOE Gb Switch w/ NM-2-10G (BH) picture

Cisco Catalyst 3850 WS-C3850-48U-S 48-Port UPOE Gb Switch w/ NM-2-10G (BH)

$134.96



Cisco WS-C3850-48F-S Catalyst 3850 48x 1GB PoE+ RJ-45 1x Module Switch picture

Cisco WS-C3850-48F-S Catalyst 3850 48x 1GB PoE+ RJ-45 1x Module Switch

$185.00



Discussions

No Discussions have been posted on this vulnerability.