Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

Gentoo: GLSA-200405-12 Critical: CVS Heap Overflow Risk Analysis

gentoo
Calendar Grey May 20, 2004
Dist Gentoo Esm H88
Debian bulletin DSA-2023-12 highlights a critical OpenSSH vulnerability. Update to the patched release promptly to prevent unauthorized access.
CVS is subject to a heap overflow vulnerability allowing source repository compromise.

Summary

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Gentoo Linux Security Advisory                           GLSA 200405-12
                                            https://security.gentoo.org/

Severity: High Title: CVS heap overflow vulnerability Date: May 20, 2004 Bugs: #51460 ID: 200405-12

Synopsis ======= CVS is subject to a heap overflow vulnerability allowing source repository compromise.
Background ========= CVS (Concurrent Versions System) is an open-source network-transparent version control system. It contains both a client utility and a server.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-util/cvs <= 1.11.15 >= 1.11.16
========== Stefan Esser discovered a heap overflow in the CVS server, which can be triggered by sending malicious "Entry" lines ...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Severity
critical
Lowest
Low
Medium
High
Critical


Warning: Undefined array key "advisory_info" in /var/www/www.linuxsecurity.com-443/html/tmp/regularlabs/custom_php/3894480_4c9dbbdde36eef04251a4ced7eac4df9 on line 11

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here