Vulnerabilities > CVE-2002-0844 - Off-by-one Error vulnerability in Distrotech CVS
Attack vector
LOCAL Attack complexity
LOW Privileges required
LOW Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
Off-by-one overflow in the CVS PreservePermissions of rcs.c for CVSD before 1.11.2 allows local users to execute arbitrary code.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Common Weakness Enumeration (CWE)
Nessus
NASL family | Red Hat Local Security Checks |
NASL id | REDHAT-RHSA-2004-004.NASL |
description | Updated cvs packages closing a vulnerability that could allow cvs to attempt to create files and directories in the root file system are now available. CVS is a version control system frequently used to manage source code repositories. A flaw was found in versions of CVS prior to 1.11.10 where a malformed module request could cause the CVS server to attempt to create files or directories at the root level of the file system. However, normal file system permissions would prevent the creation of these misplaced directories. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2003-0977 to this issue. Users of CVS are advised to upgrade to these erratum packages, which contain a patch correcting this issue. For Red Hat Enterprise Linux 2.1, these updates also fix an off-by-one overflow in the CVS PreservePermissions code. The PreservePermissions feature is not used by default (and can only be used for local CVS). The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2002-0844 to this issue. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 12446 |
published | 2004-07-06 |
reporter | This script is Copyright (C) 2004-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/12446 |
title | RHEL 2.1 / 3 : cvs (RHSA-2004:004) |
code |
|
Redhat
advisories |
| ||||
rpms | cvs-0:1.11.2-14 |
References
- ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-035.0.txt
- ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-035.0.txt
- ftp://patches.sgi.com/support/free/security/advisories/20040103-01-U.asc
- ftp://patches.sgi.com/support/free/security/advisories/20040103-01-U.asc
- http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0081.html
- http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0081.html
- http://marc.info/?l=bugtraq&m=102233767925177&w=2
- http://marc.info/?l=bugtraq&m=102233767925177&w=2
- http://www.redhat.com/support/errata/RHSA-2004-004.html
- http://www.redhat.com/support/errata/RHSA-2004-004.html
- http://www.securityfocus.com/bid/4829
- http://www.securityfocus.com/bid/4829
- https://exchange.xforce.ibmcloud.com/vulnerabilities/9175
- https://exchange.xforce.ibmcloud.com/vulnerabilities/9175