CVS (Concurrent Versions System) contains a flaw that may allow a malicious user to execude code remotely. The issue is triggered when an Argumentx command is issued which is used to add more data to a previously stored argument which is freed on client exit without checking if this list is already empty. This flaw, known as Double-free allows remote code executing resulting in a loss of integrity.
Classification
Location:
Remote/Network Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Unavailable
Disclosure:
OSVDB Verified
Solution
Upgrade to version 1.11.17 or higher if using stable, feature version 1.12.9 or higher as they have been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.