|
|
Info |
Last Modified |
| 7 months ago |
|
|
|
|
Description |
A remote overflow exists in CVS. The issue is due to a boundary error within the handling of modified or unchanged flag insertion into CVS entry lines, resulting in a heap overflow. With a specially crafted request, an attacker can cause arbitrary code execution resulting in a loss of integrity.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
|
|
Solution |
Upgrade to version 1.12.8 (feature release) or 1.11.16 (stable release) or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.
|
|
Products |
|
CVS
 |
1.11.15 |
1.12.7 |
|
|
|
|
|
|
Credit |
- Stefan Esser - sesser
hardenend-php.net - Hardened-PHP Project
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|