CVE-2004-0180

10 documents8 sources
Severity
2.6LOW
EPSS
4.2%
top 11.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 1
Latest updateMay 3

Description

The client for CVS before 1.11 allows a remote malicious CVS server to create arbitrary files using certain RCS diff files that use absolute pathnames during checkouts or updates, a different vulnerability than CVE-2004-0405.

CVSS vector

AV:N/AC:H/C:N/I:P/A:NExploitability: 4.9 | Impact: 2.9

Affected Packages2 packages

Debiancvs< 1:1.12.5-4+3
NVDcvs/cvs1.10

Patches

🔴Vulnerability Details

3
GHSA
GHSA-83qc-2j7c-2vjq: The client for CVS before 12022-05-03
OSV
CVE-2004-0180: The client for CVS before 12004-06-01
CVEList
CVE-2004-0180: The client for CVS before 12004-04-16

📋Vendor Advisories

4
BSD
FreeBSD-SA-04:07.cvs: CVS path validation errors2004-04-15
Red Hat
security flaw2004-04-14
Red Hat
security flaw2004-04-14
Debian
CVE-2004-0180: cvs - The client for CVS before 1.11 allows a remote malicious CVS server to create ar...2004

💬Community

2
Bugzilla
CVE-2004-0405 security flaw2018-08-16
Bugzilla
CVE-2004-0180 security flaw2018-08-16