CVE-2003-0977

9 documents8 sources
Severity
7.5HIGH
EPSS
1.9%
top 16.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 5
Latest updateMay 3

Description

CVS server before 1.11.10 may allow attackers to cause the CVS server to create directories and files in the file system root directory via malformed module requests.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages3 packages

Debiancvs< 1:1.11.10+3
NVDcvs/cvs10 versions+9
NVDslackware/slackware_linux8.1, 9.0, 9.1+2

Patches

🔴Vulnerability Details

3
GHSA
GHSA-4jrq-7cgx-qq88: CVS server before 12022-05-03
OSV
CVE-2003-0977: CVS server before 12004-01-05
CVEList
CVE-2003-0977: CVS server before 12003-12-10

🔍Detection Rules

1
Suricata
GPL MISC CVS non-relative path error response2010-09-23

📋Vendor Advisories

2
Red Hat
security flaw2003-12-17
Debian
CVE-2003-0977: cvs - CVS server before 1.11.10 may allow attackers to cause the CVS server to create ...2003

💬Community

2
Bugzilla
CVE-2003-0977 security flaw2018-08-16
Bugzilla
CAN-2003-0977 fix pushed for RH9, but not FC12004-03-20