This application requires Javascript for optimal performance.

CVS.Entry.Line.Flag.Remote.Heap.Overflow

Release Date

Sep 16, 2011

Severity

high

Impact

System compromise: Remote code execution.

Description

This indicates an attempt to exploit a vulnerability in Concurrent Versions System (CVS) servers.

The issue exists due to insufficient boundary checks by the application. A remote attacker can cause a heap overflow in the code that decides if a CVS entry line should have a "modified" or "unchanged" flag set. As a result the attacker may be able to execute arbitrary code on the system.

Affected Products

CVS version 1.12.7 and earlier.

Recommended Actions

Update to CVS version 1.12. or newer.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2004-0396

Reference/s

http://www.securityfocus.com/bid/10384 (BugTraq)

Reference: VID-29148