CVE-2004-0405

10 documents8 sources
Severity
5.0MEDIUM
EPSS
1.4%
top 19.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 1
Latest updateMay 3

Description

CVS before 1.11 allows CVS clients to read arbitrary files via .. (dot dot) sequences in filenames via CVS client requests, a different vulnerability than CVE-2004-0180.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

Debiancvs< 1:1.12.5-4+3
NVDcvs/cvs1.10

Patches

🔴Vulnerability Details

3
GHSA
GHSA-8j85-5mm6-6h5p: CVS before 12022-05-03
OSV
CVE-2004-0405: CVS before 12004-06-01
CVEList
CVE-2004-0405: CVS before 12004-04-17

📋Vendor Advisories

4
BSD
FreeBSD-SA-04:07.cvs: CVS path validation errors2004-04-15
Red Hat
security flaw2004-04-14
Red Hat
security flaw2004-04-14
Debian
CVE-2004-0405: cvs - CVS before 1.11 allows CVS clients to read arbitrary files via .. (dot dot) sequ...2004

💬Community

2
Bugzilla
CVE-2004-0405 security flaw2018-08-16
Bugzilla
CVE-2004-0180 security flaw2018-08-16