Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!Close

CVE-2004-0418

Published: 6 August 2004

serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote attackers to perform an "out-of-bounds" write for a single byte to execute arbitrary code or modify critical program data.

Priority

Unknown

Status

Package Release Status
cvs
Launchpad, Ubuntu, Debian
dapper
Released (1.12.9-17)
edgy
Released (1.12.9-17)
feisty
Released (1.12.9-17)
upstream Needs triage

gutsy
Released (1.12.9-17)